3.3
CVSSv3

CVE-2020-14354

Published: 13/05/2021 Updated: 07/11/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 3.3 | Impact Score: 1.4 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A possible use-after-free and double-free in c-ares lib version 1.16.0 if ares_destroy() is called prior to ares_getaddrinfo() completing. This flaw possibly allows an malicious user to crash the service that uses c-ares lib. The highest threat from this vulnerability is to this service availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

c-ares c-ares 1.16.0

fedoraproject fedora 33