Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
c-ares has a Use After Free vulnerability when connection is cleaned up after error
Vulnerability Description
c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts when using read_answer() and process_answer(), which can cause a Denial of Service. This issue is fixed in version 1.34.6.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
释放后使用
Vulnerability Title
c-ares 资源管理错误漏洞
Vulnerability Description
c-ares是c-ares个人开发者的一个用于异步 DNS 请求的 C 库。 c-ares 1.32.3版本至1.34.5版本存在资源管理错误漏洞,该漏洞源于read_answer和process_answer函数在最大尝试次数后终止查询,可能导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A