安全公告/【CVE-2023-31147】

基本信息

漏洞名称:
受影响操作系统:Asianux
危险等级:中危
影响源码包:c-ares
CVSS评分:6.5
发现日期:2023-08-30
修复版本:c-ares-1.16.1-7

漏洞描述

c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to generate random numbers used for DNS query ids. This is not a CSPRNG, and it is also not seeded by srand() so will generate predictable output. Input from the random number generator is fed into a non-compilant RC4 implementation and may not be as strong as the original RC4 implementation. No attempt is made to look for modern OS-provided CSPRNGs like arc4random() that is widely available. This issue has been fixed in version 1.19.1.

修复方式

yum update PackageName

漏洞判定

执行命令yum info PackageName获取软件包版本号,版本小于修复版本,则受此漏洞影响,版本大于等于修复版本,则此漏洞已修复

补丁

参考

https://gitee.com/src-openeuler/c-ares/issues/I77VO3
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-31147
https://nvd.nist.gov/vuln/detail/CVE-2023-31147