Wind River Support Network

HomeDefectsLIN1019-9853
Fixed

LIN1019-9853 : Security Advisory - c-ares - CVE-2023-31124

Created: May 22, 2023    Updated: Jun 20, 2023
Resolved Date: Jun 20, 2023
Found In Version: 10.19.45.1
Fix Version: 10.19.45.29
Severity: Standard
Applicable for: Wind River Linux LTS 19
Component/s: Userspace

Description

c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android.  This will downgrade to using rand() as a fallback which could allow an attacker to take advantage of the lack of entropy by not using a CSPRNG. This issue was patched in version 1.19.1.


https://nvd.nist.gov/vuln/detail/CVE-2023-31124

CVEs


Live chat
Online