CVE-2022-4904

A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 36%
Affected Products (NVD)
VendorProductVersion
c-ares_projectc-ares
𝑥
< 1.19.0
redhatsoftware_collections
-
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
c-ares
bookworm
1.18.1-3
fixed
bullseye
1.17.1-1+deb11u3
fixed
bullseye (security)
1.17.1-1+deb11u3
fixed
sid
1.34.2-1
fixed
trixie
1.34.2-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
c-ares
bionic
Fixed 1.14.0-1ubuntu0.2
released
focal
Fixed 1.15.0-1ubuntu0.2
released
jammy
Fixed 1.18.1-1ubuntu0.22.04.1
released
kinetic
Fixed 1.18.1-1ubuntu0.22.10.1
released
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
ignored
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
c-ares-devel
suse enterprise desktop 15 SP4
1.19.0-150000.3.20.1
fixed
suse enterprise desktop 15 SP5
1.19.0-150000.3.20.1
fixed
suse enterprise desktop 15 SP6
1.19.0-150000.3.20.1
fixed
suse enterprise desktop 15 SP7
1.19.0-150000.3.20.1
fixed
suse enterprise sap 15 SP1
1.19.0-150000.3.20.1
fixed
suse enterprise sap 15 SP2
1.19.0-150000.3.20.1
fixed
suse enterprise sap 15 SP3
1.19.0-150000.3.20.1
fixed
suse enterprise sap 15 SP4
1.19.0-150000.3.20.1
fixed
suse enterprise sap 15 SP5
1.19.0-150000.3.20.1
fixed
suse enterprise sap 15 SP6
1.19.0-150000.3.20.1
fixed
suse enterprise sap 15 SP7
1.19.0-150000.3.20.1
fixed
suse enterprise server 15 SP1
1.19.0-150000.3.20.1
fixed
suse enterprise server 15 SP2
1.19.0-150000.3.20.1
fixed
suse enterprise server 15 SP3
1.19.0-150000.3.20.1
fixed
suse enterprise server 15 SP4
1.19.0-150000.3.20.1
fixed
suse enterprise server 15 SP5
1.19.0-150000.3.20.1
fixed
suse enterprise server 15 SP6
1.19.0-150000.3.20.1
fixed
suse enterprise server 15 SP7
1.19.0-150000.3.20.1
fixed
libcares2
suse enterprise desktop 15 SP4
1.19.0-150000.3.20.1
fixed
suse enterprise desktop 15 SP5
1.19.0-150000.3.20.1
fixed
suse enterprise desktop 15 SP6
1.19.0-150000.3.20.1
fixed
suse enterprise desktop 15 SP7
1.19.0-150000.3.20.1
fixed
suse enterprise sap 15 SP1
1.19.0-150000.3.20.1
fixed
suse enterprise sap 15 SP2
1.19.0-150000.3.20.1
fixed
suse enterprise sap 15 SP3
1.19.0-150000.3.20.1
fixed
suse enterprise sap 15 SP4
1.19.0-150000.3.20.1
fixed
suse enterprise sap 15 SP5
1.19.0-150000.3.20.1
fixed
suse enterprise sap 15 SP6
1.19.0-150000.3.20.1
fixed
suse enterprise sap 15 SP7
1.19.0-150000.3.20.1
fixed
suse enterprise server 15 SP1
1.19.0-150000.3.20.1
fixed
suse enterprise server 15 SP2
1.19.0-150000.3.20.1
fixed
suse enterprise server 15 SP3
1.19.0-150000.3.20.1
fixed
suse enterprise server 15 SP4
1.19.0-150000.3.20.1
fixed
suse enterprise server 15 SP5
1.19.0-150000.3.20.1
fixed
suse enterprise server 15 SP6
1.19.0-150000.3.20.1
fixed
suse enterprise server 15 SP7
1.19.0-150000.3.20.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
c-ares
RHEL 8
0:1.13.0-8.el8
fixed
RHEL 8.8 AUS
0:1.13.0-6.el8_8.3
fixed
RHEL 8.8 E4S
0:1.13.0-6.el8_8.3
fixed
RHEL 8.8 EUS
0:1.13.0-6.el8_8.3
fixed
RHEL 8.8 TUS
0:1.13.0-6.el8_8.3
fixed
RHEL 9
0:1.19.1-1.el9
fixed
c-ares-devel
RHEL 8
0:1.13.0-8.el8
fixed
RHEL 8.8 AUS
0:1.13.0-6.el8_8.3
fixed
RHEL 8.8 E4S
0:1.13.0-6.el8_8.3
fixed
RHEL 8.8 EUS
0:1.13.0-6.el8_8.3
fixed
RHEL 8.8 TUS
0:1.13.0-6.el8_8.3
fixed
RHEL 9
0:1.19.1-1.el9
fixed
nodejs
RHEL 9
1:16.19.1-1.el9_2
fixed
nodejs-docs
RHEL 9
1:16.19.1-1.el9_2
fixed
nodejs-full-i18n
RHEL 9
1:16.19.1-1.el9_2
fixed
nodejs-libs
RHEL 9
1:16.19.1-1.el9_2
fixed
nodejs-nodemon
RHEL 9
0:2.0.20-3.el9_2
fixed
npm
RHEL 9
1:8.19.3-1.16.19.1.1.el9_2
fixed