Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-22949 | c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc/nsswitch.conf`, the `HOSTALIASES` file, and if using a c-ares version prior to 1.27.0, the `/etc/hosts` file. If any of these configuration files has an embedded `NULL` character as the first character in a new line, it can lead to attempting to read memory prior to the start of the given buffer which may result in a crash. This issue is fixed in c-ares 1.27.0. No known workarounds exist. |
Ubuntu USN |
USN-6676-1 | c-ares vulnerability |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 13 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 05 Feb 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
C-ares
C-ares c-ares Fedoraproject Fedoraproject fedora |
|
| Weaknesses | CWE-125 | |
| CPEs | cpe:2.3:a:c-ares:c-ares:*:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* |
|
| Vendors & Products |
C-ares
C-ares c-ares Fedoraproject Fedoraproject fedora |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-13T17:40:51.243Z
Reserved: 2024-02-08T22:26:33.512Z
Link: CVE-2024-25629
Updated: 2024-08-01T23:44:09.807Z
Status : Analyzed
Published: 2024-02-23T15:15:09.237
Modified: 2025-02-05T21:41:30.157
Link: CVE-2024-25629
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN