← Back

CVE-2021-3672

nvd nist
Published: Nov 23, 2021Modified: Jun 17, 2026

JSON object

Loading...
5.6
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitability: 2.2 / Impact: 3.4
Source: NVD

Description

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

Affected (35)

Show all products
C Ares
1 product
Fedora
12 products
Enterprise Linux
Enterprise Linux Computer Node
Enterprise Linux Eus
Enterprise Linux Server Aus
Enterprise Linux Server Tus
Enterprise Linux Tus
Enterprise Linux Workstation
1 product
1 product
Node.js
1 product
Pgbouncer
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.0.0 to 1.17.2
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 33
Version 34
Configuration C
25 vulnerable
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.0.1.1
Configuration E
5 vulnerable
Vulnerable SoftwareAffected Versions
Nodejs
From 12.0.0 to 12.12.0
From 14.0.0 to 14.14.0
From 16.0.0 to 16.6.2
From 12.13.0 to 12.22.5
From 14.15.0 to 14.17.5
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.17.0

References (10)

Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
ExploitPatchVendor Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.