Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2018:0220-1

Опубликовано: 25 янв. 2018
Источник: suse-cvrf

Описание

Security update for libevent

This update for libevent fixes the following security issues:

  • CVE-2016-10195: DNS remote stack overread vulnerability (bsc#1022917)
  • CVE-2016-10196: stack/buffer overflow in evutil_parse_sockaddr_port() (bsc#1022918)
  • CVE-2016-10197: out-of-bounds read in search_make_new() (bsc#1022919)

This update was imported from the SUSE:SLE-12:Update update project.

Список пакетов

openSUSE Leap 42.2
libevent-2.0.21-10.1
libevent-2_0-5-2.0.21-10.1
libevent-2_0-5-32bit-2.0.21-10.1
libevent-devel-2.0.21-10.1
openSUSE Leap 42.3
libevent-2.0.21-10.1
libevent-2_0-5-2.0.21-10.1
libevent-2_0-5-32bit-2.0.21-10.1
libevent-devel-2.0.21-10.1

Описание

The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_len variable, which triggers an out-of-bounds stack read.


Затронутые продукты
openSUSE Leap 42.2:libevent-2.0.21-10.1
openSUSE Leap 42.2:libevent-2_0-5-2.0.21-10.1
openSUSE Leap 42.2:libevent-2_0-5-32bit-2.0.21-10.1
openSUSE Leap 42.2:libevent-devel-2.0.21-10.1

Ссылки

Описание

Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (segmentation fault) via vectors involving a long string in brackets in the ip_as_string argument.


Затронутые продукты
openSUSE Leap 42.2:libevent-2.0.21-10.1
openSUSE Leap 42.2:libevent-2_0-5-2.0.21-10.1
openSUSE Leap 42.2:libevent-2_0-5-32bit-2.0.21-10.1
openSUSE Leap 42.2:libevent-devel-2.0.21-10.1

Ссылки

Описание

The search_make_new function in evdns.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (out-of-bounds read) via an empty hostname.


Затронутые продукты
openSUSE Leap 42.2:libevent-2.0.21-10.1
openSUSE Leap 42.2:libevent-2_0-5-2.0.21-10.1
openSUSE Leap 42.2:libevent-2_0-5-32bit-2.0.21-10.1
openSUSE Leap 42.2:libevent-devel-2.0.21-10.1

Ссылки