Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/c-ares/c-ares/issues/333 | patch issue tracking exploit |
https://lists.debian.org/debian-lts-announce/2023/09/msg00014.html | third party advisory mailing list |