← Back

CVE-2016-5180

nvd nist
Published: Oct 3, 2016Modified: May 6, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.

Affected (32)

Products: C Ares: C Ares · C Ares Project: C Ares · Debian: Debian Linux · +2 more
Show all products
1 product
C Ares
C Ares
1 product
Debian Linux
1 product
Node.js
1 product
Ubuntu Linux
Configuration A
24 vulnerable
Vulnerable SoftwareAffected Versions
C Ares
Version 1.0.0
Version 1.1.0
Version 1.10.0
Version 1.2.0
Version 1.2.1
Version 1.3.0
Version 1.3.1
Version 1.3.2
Version 1.4.0
Version 1.5.0
Version 1.5.1
Version 1.5.2
Version 1.5.3
Version 1.6.0
Version 1.7.0
Version 1.7.1
Version 1.7.2
Version 1.7.3
Version 1.7.4
Version 1.7.5
Version 1.8.0
Version 1.9.0
Version 1.9.1
Version 1.11.0
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Nodejs
From 0.10.0 to 0.10.48
From 0.12.0 to 0.12.17
From 4.0.0 to 4.6.1
Configuration D
4 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 12.04
Version 14.04
Version 16.04
Version 16.10

References (18)

Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: chrome-cve-admin@google.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.