CVE-2020-22217: C-Ares

Medium severity, CVSS 5.9. EPSS: 1% chance of exploitation in the next 30 days.

Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c.

Affected products

  • C-Ares C-Ares: version 1.16.1 only; version 1.17.0 only
  • Debian Debian Linux: version 10.0 only

Published 2023-08-22. Last modified 2026-06-17.