CVE-2016-5180 PUBLISHED

Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.

EPSS 18.16% · 95.1th percentile

Risk Scores

EPSS Score
18.16%
95.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSc-ares0, 1.10.0-2, 1.10.0-3
Ubuntu:14.04:LTSc-ares0, 1.10.0-2

Timeline

References

Open in Interactive Console →