Vulnerability Details CVE-2025-62408
c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts when using read_answer() and process_answer(), which can cause a Denial of Service. This issue is fixed in version 1.34.6.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 17.8%
CVSS Severity
CVSS v3 Score 5.9
Products affected by CVE-2025-62408
-
cpe:2.3:a:c-ares:c-ares:1.32.3
-
cpe:2.3:a:c-ares:c-ares:1.33.0
-
cpe:2.3:a:c-ares:c-ares:1.33.1
-
cpe:2.3:a:c-ares:c-ares:1.34.0
-
cpe:2.3:a:c-ares:c-ares:1.34.1
-
cpe:2.3:a:c-ares:c-ares:1.34.2
-
cpe:2.3:a:c-ares:c-ares:1.34.3
-
cpe:2.3:a:c-ares:c-ares:1.34.4
-
cpe:2.3:a:c-ares:c-ares:1.34.5