CVE-2016-5180

Priority
Description
Heap-based buffer overflow in the ares_create_query function in c-ares 1.x
before 1.12.0 allows remote attackers to cause a denial of service
(out-of-bounds write) or possibly execute arbitrary code via a hostname
with an escaped trailing dot.
Assigned-to
mdeslaur
Notes
Package
Upstream:released (1.12.0)
Ubuntu 16.04 ESM:released (1.10.0-3ubuntu0.1)
Ubuntu 14.04 ESM:DNE (trusty was released [1.10.0-2ubuntu0.1])
Patches:
Upstream:https://c-ares.haxx.se/CVE-2016-5180.patch
More Information

Updated: 2022-04-13 12:23:22 UTC (commit f411bd370d482ef4385c4e751d121a4055fbc009)