Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 754936 (CVE-2020-8277) - [Tracker] c-ares: Denial of Service with malicious DNS record (CVE-2020-8277)
Summary: [Tracker] c-ares: Denial of Service with malicious DNS record (CVE-2020-8277)
Status: RESOLVED FIXED
Alias: CVE-2020-8277
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on: 754939 754942
Blocks:
  Show dependency tree
 
Reported: 2020-11-16 16:51 UTC by Sam James
Modified: 2021-01-28 03:08 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester gentoo-dev Security 2020-11-16 16:51:27 UTC
Noticed after the nodejs security release:
"CVE-2020-8277: Denial of Service through DNS request (High). A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service by getting the application to resolve a DNS record with a larger number of responses."

Bug: https://github.com/c-ares/c-ares/issues/371
Patch: https://github.com/c-ares/c-ares/commit/0d252eb3b2147179296a3bdb4ef97883c97c54d3