[ubuntu/bionic-security] c-ares 1.14.0-1ubuntu0.1 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Tue Aug 10 11:49:31 UTC 2021


c-ares (1.14.0-1ubuntu0.1) bionic-security; urgency=medium

  * SECURITY UPDATE: Missing input validation on hostnames returned by DNS
    servers
    - debian/patches/CVE-2021-3672-1.patch: escape more characters in
      ares_expand_name.c.
    - debian/patches/CVE-2021-3672-2.patch: fix formatting and handling of
      root name response in ares_expand_name.c.
    - CVE-2021-3672

Date: 2021-08-02 12:08:14.373901+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/c-ares/1.14.0-1ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Bionic-changes mailing list