CVE-2014-6272
published 2015-08-24CVE-2014-6272: Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.1.5-beta allow context-dependent…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.08%
79.6th percentile
Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_expand, or (3) bufferevent_write function, which triggers a heap-based buffer overflow or an infinite loop. NOTE: this identifier has been SPLIT per ADT3 due to different affected versions. See CVE-2015-6525 for the functions that are only affected in 2.0 and later.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libevent | < libevent 2.0.21-stable-2 (bookworm) | libevent 2.0.21-stable-2 (bookworm) |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libevent: multiple integer overflows in the evbuffer APIs
vendor_redhat·2015-08-24·CVSS 7.5
CVE-2015-6525 [HIGH] CWE-190 libevent: multiple integer overflows in the evbuffer APIs
libevent: multiple integer overflows in the evbuffer APIs
Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_prepend, (3) evbuffer_expand, (4) exbuffer_reserve_space, or (5) evbuffer_read function, which triggers a heap-based buffer overflow or an infinite loop. NOTE: this identifier was SPLIT from CVE-2014-6272 per ADT3 due to different affected versions.
Multiple integer overflow flaws were found in the libevent's evbuffer API. An attacker able to make an application pass an excessively long input to libevent using the API could use these flaws to make the applic
Ubuntu
libevent vulnerability
vendor_ubuntu·2015-01-19
CVE-2014-6272 libevent vulnerability
Title: libevent vulnerability
Summary: libevent could be made to crash or run programs if it processed specially
crafted data.
Andrew Bartlett discovered that libevent incorrectly handled large inputs
to the evbuffer API. A remote attacker could possibly use this issue with
an application that uses libevent to cause a denial of service, or possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libevent: potential heap overflow in buffer/bufferevent APIs
vendor_redhat·2015-01-05·CVSS 7.5
CVE-2014-6272 [HIGH] CWE-190 libevent: potential heap overflow in buffer/bufferevent APIs
libevent: potential heap overflow in buffer/bufferevent APIs
Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_expand, or (3) bufferevent_write function, which triggers a heap-based buffer overflow or an infinite loop. NOTE: this identifier has been SPLIT per ADT3 due to different affected versions. See CVE-2015-6525 for the functions that are only affected in 2.0 and later.
Multiple integer overflow flaws were found in the libevent's evbuffer API. An attacker able to make an application pass an excessively long input to the libevent via evbu
Debian
CVE-2015-6525: libevent - Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 a...
vendor_debian·2015·CVSS 7.5
CVE-2015-6525 [HIGH] CVE-2015-6525: libevent - Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 a...
Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_prepend, (3) evbuffer_expand, (4) exbuffer_reserve_space, or (5) evbuffer_read function, which triggers a heap-based buffer overflow or an infinite loop. NOTE: this identifier was SPLIT from CVE-2014-6272 per ADT3 due to different affected versions.
Scope: local
bookworm: resolved (fixed in 2.0.21-stable-2)
bullseye: resolved (fixed in 2.0.21-stable-2)
forky: resolved (fixed in 2.0.21-stable-2)
sid: resolved (fixed in 2.0.21-stable-2)
trixie: resolved (fixed in 2.0.21-stable-2)
Debian
CVE-2014-6272: libevent - Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, ...
vendor_debian·2014·CVSS 7.5
CVE-2014-6272 [HIGH] CVE-2014-6272: libevent - Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, ...
Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_expand, or (3) bufferevent_write function, which triggers a heap-based buffer overflow or an infinite loop. NOTE: this identifier has been SPLIT per ADT3 due to different affected versions. See CVE-2015-6525 for the functions that are only affected in 2.0 and later.
Scope: local
bookworm: resolved (fixed in 2.0.21-stable-2)
bullseye: resolved (fixed in 2.0.21-stable-2)
forky: resolved (fixed in 2.0.21-stable-2)
sid: resolved (fixed in 2.0.21-stable-2)
trixie: resolved (fixed in 2.0.21-stable-2)
GHSA
GHSA-xfhg-qx7p-6gx5: Multiple integer overflows in the evbuffer API in Libevent 2
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2015-6525 [HIGH] GHSA-xfhg-qx7p-6gx5: Multiple integer overflows in the evbuffer API in Libevent 2
Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_prepend, (3) evbuffer_expand, (4) exbuffer_reserve_space, or (5) evbuffer_read function, which triggers a heap-based buffer overflow or an infinite loop. NOTE: this identifier was SPLIT from CVE-2014-6272 per ADT3 due to different affected versions.
GHSA
GHSA-246p-m32j-f38r: Multiple integer overflows in the evbuffer API in Libevent 1
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2014-6272 [HIGH] GHSA-246p-m32j-f38r: Multiple integer overflows in the evbuffer API in Libevent 1
Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_expand, or (3) bufferevent_write function, which triggers a heap-based buffer overflow or an infinite loop. NOTE: this identifier has been SPLIT per ADT3 due to different affected versions. See CVE-2015-6525 for the functions that are only affected in 2.0 and later.
OSV
CVE-2015-6525: Multiple integer overflows in the evbuffer API in Libevent 2
osv·2015-08-24·CVSS 7.5
CVE-2015-6525 [HIGH] CVE-2015-6525: Multiple integer overflows in the evbuffer API in Libevent 2
Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_prepend, (3) evbuffer_expand, (4) exbuffer_reserve_space, or (5) evbuffer_read function, which triggers a heap-based buffer overflow or an infinite loop. NOTE: this identifier was SPLIT from CVE-2014-6272 per ADT3 due to different affected versions.
OSV
CVE-2014-6272: Multiple integer overflows in the evbuffer API in Libevent 1
osv·2015-08-24·CVSS 7.5
CVE-2014-6272 [HIGH] CVE-2014-6272: Multiple integer overflows in the evbuffer API in Libevent 1
Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_expand, or (3) bufferevent_write function, which triggers a heap-based buffer overflow or an infinite loop. NOTE: this identifier has been SPLIT per ADT3 due to different affected versions. See CVE-2015-6525 for the functions that are only affected in 2.0 and later.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-6525 libevent: multiple integer overflows in the evbuffer APIs
bugzilla·2015-08-25·CVSS 7.5
CVE-2015-6525 [HIGH] CVE-2015-6525 libevent: multiple integer overflows in the evbuffer APIs
CVE-2015-6525 libevent: multiple integer overflows in the evbuffer APIs
Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the:
(1) evbuffer_add,
(2) evbuffer_prepend,
(3) evbuffer_expand,
(4) exbuffer_reserve_space, or
(5) evbuffer_read function,
which triggers a heap-based buffer overflow or an infinite loop.
NOTE: this identifier was SPLIT from CVE-2014-6272 per ADT3 due to different affected versions.
References:
http://archives.seul.org/libevent/users/Jan-2015/msg00010.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6525
Discussion:
Created libevent tracking bugs for this issu
Bugzilla
CVE-2014-6272 CVE-2015-6525 libevent: potential heap overflow in buffer/bufferevent APIs [fedora-all]
bugzilla·2015-01-05·CVSS 7.5
CVE-2014-6272 [HIGH] CVE-2014-6272 CVE-2015-6525 libevent: potential heap overflow in buffer/bufferevent APIs [fedora-all]
CVE-2014-6272 CVE-2015-6525 libevent: potential heap overflow in buffer/bufferevent APIs [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2014-6272 libevent: potential heap overflow in buffer/bufferevent APIs
bugzilla·2014-09-20·CVSS 7.5
CVE-2014-6272 [HIGH] CVE-2014-6272 libevent: potential heap overflow in buffer/bufferevent APIs
CVE-2014-6272 libevent: potential heap overflow in buffer/bufferevent APIs
A defect in the Libevent evbuffer API could possibly leave some programs that use the evbuffer API open to potential heap overflows. A program using the evbuffer_add(), evbuffer_expand(), or bufferevent_write() functions in Libevent 1.4 may be vulnerable if an attacker is able to coax the linked program into trying to make a buffer larger than that which would fit into a single size_t. Similarly, for Libevent 2.0 and later, a program may be vulnerable if it uses the evbuffer_add(), evbuffer_prepend(), evbuffer_expand(), exbuffer_reserve_space(), or evbuffer_read() functions if an attacker is able to coax the linked program into trying to make a buffer chunk larger than that which will fit into a single size_t.
Ups
http://archives.seul.org/libevent/users/Jan-2015/msg00010.htmlhttp://www.debian.org/security/2015/dsa-3119http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.366317https://puppet.com/security/cve/CVE-2014-6272http://archives.seul.org/libevent/users/Jan-2015/msg00010.htmlhttp://www.debian.org/security/2015/dsa-3119http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.366317https://puppet.com/security/cve/CVE-2014-6272
2015-08-24
Published