CVE-2014-6272
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD
Description
Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_expand, or (3) bufferevent_write function, which triggers a heap-based buffer overflow or an infinite loop. NOTE: this identifier has been SPLIT per ADT3 due to different affected versions. See CVE-2015-6525 for the functions that are only affected in 2.0 and later.
Affected (41)
Products: Debian: Debian Linux · Libevent Project: Libevent
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.0 |
Related CWEs
References (8)
Source: security@debian.org
Vendor Advisory
Source: security@debian.org
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.366317
Source: security@debian.org
Source: security@debian.org
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.366317
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.