5.6
CVSSv3

CVE-2021-3672

Published: 23/11/2021 Updated: 05/01/2024
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.6 | Impact Score: 3.4 | Exploitability Score: 2.2
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

c-ares project c-ares

fedoraproject fedora 33

fedoraproject fedora 34

redhat enterprise linux 7.0

redhat enterprise linux 8.0

redhat enterprise linux eus 7.7

redhat enterprise linux 7.7

redhat enterprise linux eus 8.1

redhat enterprise linux eus 8.2

redhat enterprise linux server tus 8.2

redhat enterprise linux server aus 8.2

redhat enterprise linux tus 8.4

redhat enterprise linux server tus 8.4

redhat enterprise linux eus 8.4

redhat enterprise linux server aus 8.4

redhat enterprise linux server update services for sap solutions 8.2

redhat enterprise linux server update services for sap solutions 8.4

redhat enterprise linux server update services for sap solutions 8.1

redhat enterprise linux for power little endian eus 8.2

redhat enterprise linux for ibm z systems eus 8.2

redhat enterprise linux for ibm z systems eus 8.1

redhat enterprise linux for power little endian eus 8.1

redhat enterprise linux for power little endian 8.0

redhat enterprise linux for ibm z systems eus 8.4

redhat enterprise linux for ibm z systems 8.0

redhat enterprise linux for power little endian eus 8.4

redhat enterprise linux computer node 1

redhat enterprise linux workstation 1

siemens sinec infrastructure network services

nodejs node.js

pgbouncer pgbouncer

Vendor Advisories

Debian Bug report logs - #992053 c-ares: CVE-2021-3672: Missing input validation on hostnames returned by DNS servers Package: src:c-ares; Maintainer for src:c-ares is Gregor Jasny <gjasny@googlemailcom>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 10 Aug 2021 06:27:01 UTC Severity: grave Tags: ...
Philipp Jeitner and Haya Shulman discovered a flaw in c-ares, a library that performs DNS requests and name resolution asynchronously Missing input validation of hostnames returned by DNS servers can lead to output of wrong hostnames (leading to Domain Hijacking) For the stable distribution (buster), this problem has been fixed in version 1140- ...
Synopsis Moderate: ACS 370 enhancement and security update Type/Severity Security Advisory: Moderate Topic Updated images are now available for Red Hat Advanced Cluster Security forKubernetes (RHACS) The updated image includes bug fixes and featureimprovementsRed Hat Product Security has rated this update as having a security impact of Mod ...
Synopsis Moderate: c-ares security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for c-ares is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a secu ...
Synopsis Important: RHACS 369 security update Type/Severity Security Advisory: Important Topic Updated images are now available for Red Hat Advanced Cluster Security for Kubernetes (RHACS) The updated image includes bug and security fixesRed Hat Product Security has rated this update as having a security impact of Important A Common Vulne ...
Synopsis Important: RHACS 368 security update Type/Severity Security Advisory: Important Topic Updated images are now available for Red Hat Advanced Cluster Security for Kubernetes (RHACS) The updated image includes bug and security fixesRed Hat Product Security has rated this update as having a security impact of Important A Common Vulne ...
Synopsis Important: OpenShift Container Platform 4110 bug fix and security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 4110 is now available withupdates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Co ...
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking The highest threat from this vulnerability is to confidentiality and integrity as well as system availability (CVE-2021-3672) A flaw w ...
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking The highest threat from this vulnerability is to confidentiality and integrity as well as system availability (CVE-2021-3672) ...
No description is available for this CVE ...
Missing input validation of host names returned by Domain Name Servers in the c-ares library before version 1172 can lead to output of wrong hostnames (leading to Domain Hijacking) ...

ICS Advisories

Siemens SINEC INS
Critical Infrastructure Sectors: Energy