Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-10197

Опубликовано: 03 мар. 2016
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

The search_make_new function in evdns.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (out-of-bounds read) via an empty hostname.

An out of bounds read vulnerability was found in libevent in the search_make_new function. If an attacker could cause an application using libevent to attempt resolving an empty hostname, an out of bounds read could occur possibly leading to a crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5firefoxWill not fix
Red Hat Enterprise Linux 5libeventWill not fix
Red Hat Enterprise Linux 5nfs-utilsNot affected
Red Hat Enterprise Linux 5openmpiNot affected
Red Hat Enterprise Linux 5thunderbirdWill not fix
Red Hat Enterprise Linux 6chromium-browserNot affected
Red Hat Enterprise Linux 6libeventWill not fix
Red Hat Enterprise Linux 6nfs-utilsNot affected
Red Hat Enterprise Linux 6openmpiNot affected
Red Hat Enterprise Linux 7libeventWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1418612libevent: Out-of-bounds read in search_make_new()

EPSS

Процентиль: 80%
0.01446
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

The search_make_new function in evdns.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (out-of-bounds read) via an empty hostname.

CVSS3: 7.5
nvd
больше 8 лет назад

The search_make_new function in evdns.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (out-of-bounds read) via an empty hostname.

CVSS3: 7.5
debian
больше 8 лет назад

The search_make_new function in evdns.c in libevent before 2.1.6-beta ...

CVSS3: 7.5
github
около 3 лет назад

The search_make_new function in evdns.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (out-of-bounds read) via an empty hostname.

suse-cvrf
больше 7 лет назад

Security update for libevent

EPSS

Процентиль: 80%
0.01446
Низкий

7.5 High

CVSS3