Security update for libcares2
This update for libcares2 fixes the following issues: - CVE-2023-32067: Fixed a denial of service that could be triggered by a 0-byte UDP payload (bsc#1211604). - CVE-2023-31147: Fixed an insufficient randomness in generation of DNS query IDs (bsc#1211605). - CVE-2023-31130: Fixed a buffer underflow when configuring specific IPv6 addresses (bsc#1211606). - CVE-2023-31124: Fixed a build issue when cross-compiling that could lead to insufficient randomness (bsc#1211607).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for libcares2 fixes the following issues: - CVE-2023-32067: Fixed a denial of service that could be triggered by a 0-byte UDP payload (bsc#1211604). - CVE-2023-31147: Fixed an insufficient randomness in generation of DNS query IDs (bsc#1211605). - CVE-2023-31130: Fixed a buffer underflow when configuring specific IPv6 addresses (bsc#1211606). - CVE-2023-31124: Fixed a build issue when cross-compiling that could lead to insufficient randomness (bsc#1211607).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1211604
- https://bugzilla.suse.com/1211605
- https://bugzilla.suse.com/1211606
- https://bugzilla.suse.com/1211607
- https://www.suse.com/security/cve/CVE-2023-31124
- https://www.suse.com/security/cve/CVE-2023-31130
- https://www.suse.com/security/cve/CVE-2023-31147
- https://www.suse.com/security/cve/CVE-2023-32067
- https://www.suse.com/support/update/announcement/2023/suse-su-20232477-1/