Denial of Service Vulnerability in c-ares Library by c-ares
CVE-2025-62408
5.9MEDIUM
What is CVE-2025-62408?
The c-ares library is an asynchronous resolver used widely in various applications. Versions 1.32.3 to 1.34.5 have a fault in their read_answer() and process_answer() functions, causing them to terminate a query prematurely after the maximum number of attempts. This behavior can lead to a Denial of Service, making the application susceptible to interruptions. Users are encouraged to upgrade to version 1.34.6 or later to mitigate this issue.
Affected Version(s)
c-ares > 1.32.3, < 1.34.6
