node/deps/cares/src
Daniel Stenberg c5643a8f02 ares_create_query: avoid single-byte buffer overwrite
Incorrect string length calculation when passing escaped dot.

- CVE: CVE-2016-5180
- Upstream bug: https://c-ares.haxx.se/adv_20160929.html

PR-URL: https://github.com/nodejs/node/pull/8849
Reviewed-By: Myles Borins <myles.borins@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Johan Bergström <bugs@bergstroem.nu>
Reviewed-By: Fedor Indutny <fedor.indutny@gmail.com>
2016-10-06 11:49:01 -07:00
..
ares__close_sockets.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares__get_hostent.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares__read_line.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares__timeval.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_cancel.c deps: upgrade c-ares to 1.10.0 2013-05-14 02:07:35 +02:00
ares_create_query.c ares_create_query: avoid single-byte buffer overwrite 2016-10-06 11:49:01 -07:00
ares_data.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_data.h deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_destroy.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_dns.h deps: upgrade c-ares to 1.10.0 2013-05-14 02:07:35 +02:00
ares_expand_name.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_expand_string.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_fds.c deps: upgrade c-ares to 1.10.0 2013-05-14 02:07:35 +02:00
ares_free_hostent.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_free_string.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_getenv.c Add c-ares dependency 2012-08-07 01:49:02 +02:00
ares_getenv.h Add c-ares dependency 2012-08-07 01:49:02 +02:00
ares_gethostbyaddr.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_gethostbyname.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_getnameinfo.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_getopt.c Add c-ares dependency 2012-08-07 01:49:02 +02:00
ares_getopt.h Add c-ares dependency 2012-08-07 01:49:02 +02:00
ares_getsock.c deps: sync with upstream bagder/c-ares@bba4dc5 2015-05-12 10:46:57 +02:00
ares_inet_net_pton.h deps: upgrade c-ares to 1.10.0 2013-05-14 02:07:35 +02:00
ares_init.c deps: reapply c-ares floating patch 2016-02-11 22:23:48 -05:00
ares_iphlpapi.h Add c-ares dependency 2012-08-07 01:49:02 +02:00
ares_ipv6.h deps: sync with upstream bagder/c-ares@bba4dc5 2015-05-12 10:46:57 +02:00
ares_library_init.c src,deps: replace LoadLibrary by LoadLibraryW 2016-02-08 14:44:40 -05:00
ares_library_init.h Add c-ares dependency 2012-08-07 01:49:02 +02:00
ares_llist.c deps: upgrade c-ares to 1.10.0 2013-05-14 02:07:35 +02:00
ares_llist.h deps: upgrade c-ares to 1.10.0 2013-05-14 02:07:35 +02:00
ares_mkquery.c deps: upgrade c-ares to 1.10.0 2013-05-14 02:07:35 +02:00
ares_nowarn.c deps: sync with upstream bagder/c-ares@bba4dc5 2015-05-12 10:46:57 +02:00
ares_nowarn.h Add c-ares dependency 2012-08-07 01:49:02 +02:00
ares_options.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_parse_a_reply.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_parse_aaaa_reply.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_parse_mx_reply.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_parse_naptr_reply.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_parse_ns_reply.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_parse_ptr_reply.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_parse_soa_reply.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_parse_srv_reply.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_parse_txt_reply.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_platform.c Add c-ares dependency 2012-08-07 01:49:02 +02:00
ares_platform.h Add c-ares dependency 2012-08-07 01:49:02 +02:00
ares_private.h deps: sync with upstream c-ares/c-ares@4ef6817 2016-02-11 22:23:48 -05:00
ares_process.c deps: sync with upstream c-ares/c-ares@4ef6817 2016-02-11 22:23:48 -05:00
ares_query.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_search.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_send.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_setup.h deps: sync with upstream bagder/c-ares@bba4dc5 2015-05-12 10:46:57 +02:00
ares_strcasecmp.c Add c-ares dependency 2012-08-07 01:49:02 +02:00
ares_strcasecmp.h Add c-ares dependency 2012-08-07 01:49:02 +02:00
ares_strdup.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_strdup.h deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_strerror.c Add c-ares dependency 2012-08-07 01:49:02 +02:00
ares_timeout.c deps: sync with upstream bagder/c-ares@bba4dc5 2015-05-12 10:46:57 +02:00
ares_version.c Add c-ares dependency 2012-08-07 01:49:02 +02:00
ares_writev.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
ares_writev.h Add c-ares dependency 2012-08-07 01:49:02 +02:00
AUTHORS deps: upgrade c-ares to 1.10.0 2013-05-14 02:07:35 +02:00
bitncmp.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
bitncmp.h deps: upgrade c-ares to 1.10.0 2013-05-14 02:07:35 +02:00
config-win32.h deps: sync with upstream bagder/c-ares@bba4dc5 2015-05-12 10:46:57 +02:00
inet_net_pton.c deps: sync with upstream bagder/c-ares@2bae2d5 2016-02-08 14:44:19 -05:00
inet_ntop.c deps: upgrade c-ares to 1.10.0 2013-05-14 02:07:35 +02:00
NEWS Add c-ares dependency 2012-08-07 01:49:02 +02:00
README deps: upgrade c-ares to 1.10.0 2013-05-14 02:07:35 +02:00
README.cares Add c-ares dependency 2012-08-07 01:49:02 +02:00
README.msvc Add c-ares dependency 2012-08-07 01:49:02 +02:00
RELEASE-NOTES deps: upgrade c-ares to 1.10.0 2013-05-14 02:07:35 +02:00
setup_once.h deps: upgrade c-ares to 1.10.0 2013-05-14 02:07:35 +02:00
TODO Add c-ares dependency 2012-08-07 01:49:02 +02:00
windows_port.c Add c-ares dependency 2012-08-07 01:49:02 +02:00

c-ares
======

This is c-ares, an asynchronous resolver library.  It is intended for
applications which need to perform DNS queries without blocking, or need to
perform multiple DNS queries in parallel.  The primary examples of such
applications are servers which communicate with multiple clients and programs
with graphical user interfaces.

The full source code is available in the 'c-ares' release archives, and in a
git repository: http://github.com/bagder/c-ares

If you find bugs, correct flaws, have questions or have comments in general in
regard to c-ares (or by all means the original ares too), get in touch with us
on the c-ares mailing list: http://cool.haxx.se/mailman/listinfo/c-ares

c-ares is of course distributed under the same MIT-style license as the
original ares.

You'll find all c-ares details and news here:

        http://c-ares.haxx.se/


NOTES FOR C-ARES HACKERS

* The distributed ares_build.h file is only intended to be used on systems
  which can not run the also distributed configure script.

* The distributed ares_build.h file is generated as a copy of ares_build.h.dist
  when the c-ares source code distribution archive file is originally created.

* If you check out from git on a non-configure platform, you must run the
  appropriate buildconf* script to set up ares_build.h and other local files
  before being able of compiling the library.

* On systems capable of running the configure script, the configure process
  will overwrite the distributed ares_build.h file with one that is suitable
  and specific to the library being configured and built, this new file is
  generated from the ares_build.h.in template file.

* If you intend to distribute an already compiled c-ares library you _MUST_
  also distribute along with it the generated ares_build.h which has been
  used to compile it. Otherwise the library will be of no use for the users of
  the library that you have built. It is _your_ responsibility to provide this
  file. No one at the c-ares project can know how you have built the library.

* File ares_build.h includes platform and configuration dependent info,
  and must not be modified by anyone. Configure script generates it for you.

* We cannot assume anything else but very basic compiler features being
  present. While c-ares requires an ANSI C compiler to build, some of the
  earlier ANSI compilers clearly can't deal with some preprocessor operators.

* Newlines must remain unix-style for older compilers' sake.

* Comments must be written in the old-style /* unnested C-fashion */