========================================================================== Ubuntu Security Notice USN-6164-1 June 14, 2023 c-ares vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 - Ubuntu 22.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in c-ares. Software Description: - c-ares: library for asynchronous name resolution Details: Hannes Moesl discovered that c-ares incorrectly handled certain ipv6 addresses. An attacker could use this issue to cause c-ares to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-31130) Xiang Li discovered that c-ares incorrectly handled certain UDP packets. A remote attacker could possibly use this issue to cause c-res to crash, resulting in a denial of service. (CVE-2023-32067) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: libc-ares2 1.18.1-2ubuntu0.1 Ubuntu 22.10: libc-ares2 1.18.1-1ubuntu0.22.10.2 Ubuntu 22.04 LTS: libc-ares2 1.18.1-1ubuntu0.22.04.2 Ubuntu 20.04 LTS: libc-ares2 1.15.0-1ubuntu0.3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6164-1 CVE-2023-31130, CVE-2023-32067 Package Information: https://launchpad.net/ubuntu/+source/c-ares/1.18.1-2ubuntu0.1 https://launchpad.net/ubuntu/+source/c-ares/1.18.1-1ubuntu0.22.10.2 https://launchpad.net/ubuntu/+source/c-ares/1.18.1-1ubuntu0.22.04.2 https://launchpad.net/ubuntu/+source/c-ares/1.15.0-1ubuntu0.3