c-ares.c-ares is vulnerable to Use After Free
83
High Risk
When process_answer() queues a query again after a DNS cookie failure, missing EDNS support, or a TCP close right after the response, a failed send closes the connection. read_answers() still reads that closed connection to dequeue other responses, a use-after-free that crashes the process. The fix stops reading the connection once it has been closed.
You are affected if you are using a version that falls within the vulnerable range.
c-ares.c-ares is vulnerable to Use After Free in versions 1.32.3 - 1.34.4.
Upgrade the c-ares.c-ares and/or the c-ares library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.