CVE-2023-31147 is a medium-severity vulnerability affecting the c-ares asynchronous resolver library, as well as Fedora Project's c-ares and Fedora distributions. The flaw stems from insufficient randomness in generating DNS query identifiers when /dev/urandom or RtlGenRandom() are unavailable, leading to predictable output due to the use of a non-cryptographically secure pseudorandom number generator (rand()) and a non-compliant RC4 implementation. This vulnerability has a CVSS score of 6.5, indicating a network-based attack with low complexity that could result in limited confidentiality and integrity impacts. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the KEV catalog, though it has garnered some community discussion and media coverage. The issue has been patched in c-ares version 1.19.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.19.1CPE matchmatch criteria | cpe:2.3:a:c-ares_project:c-ares:*:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.