Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

C-Ares version update for buffer overflow vulnerability fix? #11728

Closed
Mickael-van-der-Beek opened this issue Mar 7, 2017 · 2 comments
Closed
Labels
cares Issues and PRs related to the c-ares dependency or the cares_wrap binding. question Issues that look for answers. security Issues and PRs related to security.

Comments

@Mickael-van-der-Beek
Copy link

I was wondering if there were any plans for Node.js to update the C-Ares version from 1.10.0 to 1.12.0 so as to take into account the fix for the buffer overflow vulnerability (CVE-2016-5180)?

CVE-2016-5180: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5180
C-Ares Advisory: https://c-ares.haxx.se/adv_20160929.html
C-Ares Patch: https://c-ares.haxx.se/CVE-2016-5180.patch

@addaleax addaleax added cares Issues and PRs related to the c-ares dependency or the cares_wrap binding. question Issues that look for answers. security Issues and PRs related to security. labels Mar 7, 2017
@addaleax
Copy link
Member

addaleax commented Mar 7, 2017

I think this particular problem was addressed by 68c4c71 (#8849)?

@Mickael-van-der-Beek
Copy link
Author

@addaleax My bad I was looking at the version and not at the patch indeed. Thank you for the fast answer!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
cares Issues and PRs related to the c-ares dependency or the cares_wrap binding. question Issues that look for answers. security Issues and PRs related to security.
Projects
None yet
Development

No branches or pull requests

2 participants