MGASA-2015-0009
Dashboard / Vulnerabilities / MGASA-2015-0009
Summary: Updated libevent packages fix CVE-2014-6272
Details: Updated libevent packages fix security vulnerability: Andrew Bartlett of Catalyst reported a defect affecting certain applications using the Libevent evbuffer API. This defect leaves applications which pass insanely large inputs to evbuffers open to a possible heap overflow or infinite loop. In order to exploit this flaw, an attacker needs to be able to find a way to provoke the program into trying to make a buffer chunk larger than what will fit into a single size_t or off_t (CVE-2014-6272).
References: https://advisories.mageia.org/MGASA-2015-0009.html, https://bugs.mageia.org/show_bug.cgi?id=14970, https://www.debian.org/security/2015/dsa-3119
Affected packages
Package
Name: libevent
Purl: pkg:rpm/mageia/libevent?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
