ALAS-2024-2429

Related Vulnerabilities: CVE-2023-31124  

When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android. This will downgrade to using rand() as a fallback which could allow an attacker to take advantage of the lack of entropy by not using a CSPRNG. (CVE-2023-31124)

ALAS-2024-2429


Amazon Linux 2 Security Advisory: ALAS-2024-2429
Advisory Release Date: 2024-01-19 01:51 Pacific
Advisory Updated Date: 2024-01-22 20:21 Pacific
Severity: Low

Issue Overview:

When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android. This will downgrade to using rand() as a fallback which could allow an attacker to take advantage of the lack of entropy by not using a CSPRNG. (CVE-2023-31124)


Affected Packages:

c-ares


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update c-ares to update your system.

New Packages:
aarch64:
    c-ares-1.10.0-3.amzn2.0.5.aarch64
    c-ares-devel-1.10.0-3.amzn2.0.5.aarch64
    c-ares-debuginfo-1.10.0-3.amzn2.0.5.aarch64

i686:
    c-ares-1.10.0-3.amzn2.0.5.i686
    c-ares-devel-1.10.0-3.amzn2.0.5.i686
    c-ares-debuginfo-1.10.0-3.amzn2.0.5.i686

src:
    c-ares-1.10.0-3.amzn2.0.5.src

x86_64:
    c-ares-1.10.0-3.amzn2.0.5.x86_64
    c-ares-devel-1.10.0-3.amzn2.0.5.x86_64
    c-ares-debuginfo-1.10.0-3.amzn2.0.5.x86_64