PT-2016-4581 · Libevent+4 · Libevent+4

Guido Vranken

·

Published

2016-12-31

·

Updated

2022-01-31

·

CVE-2016-10195

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libevent versions prior to 2.1.6-beta
Description The issue is related to the name parse function in evdns.c, which allows remote attackers to have an unspecified impact via vectors involving the label len variable. This triggers an out-of-bounds stack read.
Recommendations For versions prior to 2.1.6-beta, update to version 2.1.6-beta or later to resolve the issue. As a temporary workaround, consider restricting access to the name parse function in evdns.c to minimize the risk of exploitation.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2017_1104
CESA-2017_1106
CESA-2017_1201
CVE-2016-10195
DLA-824-1
DSA-3789-1
MGASA-2017-0066
RHSA-2017:1104
RHSA-2017:1106
RHSA-2017:1201
RHSA-2017_1104
RHSA-2017_1106
RHSA-2017_1201
SUSE-SU-2018:0200-1
SUSE-SU-2018:0263-1
SUSE-SU-2018_0200-1
SUSE-SU-2018_0263-1
USN-3228-1
USN-3278-1

Affected Products

Centos
Red Hat
Suse
Ubuntu
Libevent