HIGH 8.6 Microsoft

CVE-2022-4904

A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.

Microsoft Security Update 2023-Mar: A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.

Affected Products

References

Published: 2023-03-14 · Source: Microsoft · Feed updated: 2026-09-17
This high severity vulnerability with a CVSS score of 8.6 was published on 2023-03-14 via Microsoft. Affected: azl3 grpc 1.42.0-7 on Azure Linux 3.0, cm1 python-gevent 1.3.6-5 on CBL Mariner 1.0, cm1 nodejs 14.21.3-1 on CBL Mariner 1.0 and 5 more.
vulnfeed aggregates 8294 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.