Bug 1220279 (CVE-2024-25629) - VUL-0: CVE-2024-25629: c-ares: out of bounds read in ares__read_line()
Summary: VUL-0: CVE-2024-25629: c-ares: out of bounds read in ares__read_line()
Status: RESOLVED FIXED
Alias: CVE-2024-25629
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/394959/
Whiteboard: CVSSv3.1:SUSE:CVE-2024-25629:4.4:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2024-02-23 13:57 UTC by SMASH SMASH
Modified: 2024-07-12 16:31 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2024-02-23 13:57:27 UTC
|ares__read_line()|is used to parse local configuration files such 
as|/etc/resolv.conf|,|/etc/nsswitch.conf|, the|HOSTALIASES|file, and if 
using a c-ares version prior to 1.22.0, the|/etc/hosts|file. If any of 
these configuration files has an embedded|NULL|character as the first 
character in a new line, it can lead...

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-25629
https://seclists.org/oss-sec/2024/q1/157
https://github.com/c-ares/c-ares/security/advisories/GHSA-mg26-v6qh-x48q

Patch:
https://github.com/c-ares/c-ares/commit/a804c04ddc8245fc8adf0e92368709639125e183
Comment 1 Andrea Mattiazzo 2024-02-23 13:57:58 UTC
Tracking as affected:
- SUSE:ALP:Source:Standard:1.0/c-ares  1.19.1
- SUSE:SLE-15:Update/c-ares            1.19.1
- openSUSE:Factory/c-ares              1.26.0
Comment 2 Adam Majer 2024-02-26 13:23:38 UTC
Also affected is libcares2 in SLE-12
Comment 5 OBSbugzilla Bot 2024-02-26 15:35:02 UTC
This is an autogenerated message for OBS integration:
This bug (1220279) was mentioned in
https://build.opensuse.org/request/show/1151588 Factory / c-ares
Comment 6 Maintenance Automation 2024-04-08 12:31:07 UTC
SUSE-SU-2024:1136-1: An update that solves one vulnerability can now be installed.

Category: security (moderate)
Bug References: 1220279
CVE References: CVE-2024-25629
Maintenance Incident: [SUSE:Maintenance:32784](https://smelt.suse.de/incident/32784/)
Sources used:
openSUSE Leap Micro 5.3 (src):
 c-ares-1.19.1-150000.3.26.1
openSUSE Leap Micro 5.4 (src):
 c-ares-1.19.1-150000.3.26.1
openSUSE Leap 15.5 (src):
 c-ares-1.19.1-150000.3.26.1
SUSE Linux Enterprise Micro for Rancher 5.3 (src):
 c-ares-1.19.1-150000.3.26.1
SUSE Linux Enterprise Micro 5.3 (src):
 c-ares-1.19.1-150000.3.26.1
SUSE Linux Enterprise Micro for Rancher 5.4 (src):
 c-ares-1.19.1-150000.3.26.1
SUSE Linux Enterprise Micro 5.4 (src):
 c-ares-1.19.1-150000.3.26.1
SUSE Linux Enterprise Micro 5.5 (src):
 c-ares-1.19.1-150000.3.26.1
Basesystem Module 15-SP5 (src):
 c-ares-1.19.1-150000.3.26.1
SUSE Linux Enterprise Micro 5.1 (src):
 c-ares-1.19.1-150000.3.26.1
SUSE Linux Enterprise Micro 5.2 (src):
 c-ares-1.19.1-150000.3.26.1
SUSE Linux Enterprise Micro for Rancher 5.2 (src):
 c-ares-1.19.1-150000.3.26.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Maintenance Automation 2024-04-08 12:31:09 UTC
SUSE-SU-2024:1135-1: An update that solves one vulnerability can now be installed.

Category: security (moderate)
Bug References: 1220279
CVE References: CVE-2024-25629
Maintenance Incident: [SUSE:Maintenance:32783](https://smelt.suse.de/incident/32783/)
Sources used:
SUSE Linux Enterprise Software Development Kit 12 SP5 (src):
 libcares2-1.9.1-9.21.1
SUSE Linux Enterprise High Performance Computing 12 SP5 (src):
 libcares2-1.9.1-9.21.1
SUSE Linux Enterprise Server 12 SP5 (src):
 libcares2-1.9.1-9.21.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5 (src):
 libcares2-1.9.1-9.21.1
SUSE Linux Enterprise Workstation Extension 12 12-SP5 (src):
 libcares2-1.9.1-9.21.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Maintenance Automation 2024-07-12 16:31:13 UTC
SUSE-SU-2024:1136-2: An update that solves one vulnerability can now be installed.

Category: security (moderate)
Bug References: 1220279
CVE References: CVE-2024-25629
Maintenance Incident: [SUSE:Maintenance:32784](https://smelt.suse.de/incident/32784/)
Sources used:
SUSE Linux Enterprise Micro 5.5 (src):
 c-ares-1.19.1-150000.3.26.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.