CVE-2017-1000381: C-Ares
High severity, CVSS 7.5. EPSS: 3.3% chance of exploitation in the next 30 days.
The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS response packet was crafted in a particular way.
Affected products
- C-Ares C-Ares: version 1.8.0 only; version 1.9.0 only; version 1.9.1 only; version 1.10.0 only; version 1.12.0 only
- C-Ares Project C-Ares: version 1.11.0 only
- Node.js Node.js: from 4.0.0, up to and including 4.1.2; from 4.2.0, before 4.8.4 (fixed in 4.8.4); from 5.0.0, up to and including 5.12.0; from 6.0.0, up to and including 6.8.1; from 6.9.0, before 6.11.1 (fixed in 6.11.1); from 7.0.0, before 7.10.1 (fixed in 7.10.1); …
Published 2017-07-07. Last modified 2026-06-17.