PT-2016-4582 · Nick Mathewson+4 · Libevent+4

Guido Vranken

·

Published

2016-12-31

·

Updated

2022-01-31

·

CVE-2016-10197

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libevent versions prior to 2.1.6-beta
Description The issue allows attackers to cause a denial of service (out-of-bounds read) via an empty hostname. This is related to the search make new function in evdns.c.
Recommendations For versions prior to 2.1.6-beta, update to version 2.1.6-beta or later to resolve the issue. As a temporary workaround, consider restricting the input to the search make new function to prevent empty hostnames.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2017_1104
CESA-2017_1106
CESA-2017_1201
CVE-2016-10197
DLA-824-1
DSA-3789-1
MGASA-2017-0066
RHSA-2017:1104
RHSA-2017:1106
RHSA-2017:1201
RHSA-2017_1104
RHSA-2017_1106
RHSA-2017_1201
SUSE-SU-2018:0200-1
SUSE-SU-2018:0263-1
USN-3228-1
USN-3278-1

Affected Products

Centos
Red Hat
Suse
Ubuntu
Libevent