CVE-2015-6525
published 2015-08-24CVE-2015-6525: Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial…
PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.81%
91.0th percentile
Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_prepend, (3) evbuffer_expand, (4) exbuffer_reserve_space, or (5) evbuffer_read function, which triggers a heap-based buffer overflow or an infinite loop. NOTE: this identifier was SPLIT from CVE-2014-6272 per ADT3 due to different affected versions.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libevent | < libevent 2.0.21-stable-2 (bookworm) | libevent 2.0.21-stable-2 (bookworm) |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
| libevent_project | libevent | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libevent: multiple integer overflows in the evbuffer APIs
vendor_redhat·2015-08-24·CVSS 7.5
CVE-2015-6525 [HIGH] CWE-190 libevent: multiple integer overflows in the evbuffer APIs
libevent: multiple integer overflows in the evbuffer APIs
Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_prepend, (3) evbuffer_expand, (4) exbuffer_reserve_space, or (5) evbuffer_read function, which triggers a heap-based buffer overflow or an infinite loop. NOTE: this identifier was SPLIT from CVE-2014-6272 per ADT3 due to different affected versions.
Multiple integer overflow flaws were found in the libevent's evbuffer API. An attacker able to make an application pass an excessively long input to libevent using the API could use these flaws to make the applic
Red Hat
libevent: potential heap overflow in buffer/bufferevent APIs
vendor_redhat·2015-01-05·CVSS 7.5
CVE-2014-6272 [HIGH] CWE-190 libevent: potential heap overflow in buffer/bufferevent APIs
libevent: potential heap overflow in buffer/bufferevent APIs
Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_expand, or (3) bufferevent_write function, which triggers a heap-based buffer overflow or an infinite loop. NOTE: this identifier has been SPLIT per ADT3 due to different affected versions. See CVE-2015-6525 for the functions that are only affected in 2.0 and later.
Multiple integer overflow flaws were found in the libevent's evbuffer API. An attacker able to make an application pass an excessively long input to the libevent via evbu
Debian
CVE-2015-6525: libevent - Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 a...
vendor_debian·2015·CVSS 7.5
CVE-2015-6525 [HIGH] CVE-2015-6525: libevent - Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 a...
Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_prepend, (3) evbuffer_expand, (4) exbuffer_reserve_space, or (5) evbuffer_read function, which triggers a heap-based buffer overflow or an infinite loop. NOTE: this identifier was SPLIT from CVE-2014-6272 per ADT3 due to different affected versions.
Scope: local
bookworm: resolved (fixed in 2.0.21-stable-2)
bullseye: resolved (fixed in 2.0.21-stable-2)
forky: resolved (fixed in 2.0.21-stable-2)
sid: resolved (fixed in 2.0.21-stable-2)
trixie: resolved (fixed in 2.0.21-stable-2)
Debian
CVE-2014-6272: libevent - Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, ...
vendor_debian·2014·CVSS 7.5
CVE-2014-6272 [HIGH] CVE-2014-6272: libevent - Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, ...
Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_expand, or (3) bufferevent_write function, which triggers a heap-based buffer overflow or an infinite loop. NOTE: this identifier has been SPLIT per ADT3 due to different affected versions. See CVE-2015-6525 for the functions that are only affected in 2.0 and later.
Scope: local
bookworm: resolved (fixed in 2.0.21-stable-2)
bullseye: resolved (fixed in 2.0.21-stable-2)
forky: resolved (fixed in 2.0.21-stable-2)
sid: resolved (fixed in 2.0.21-stable-2)
trixie: resolved (fixed in 2.0.21-stable-2)
GHSA
GHSA-xfhg-qx7p-6gx5: Multiple integer overflows in the evbuffer API in Libevent 2
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2015-6525 [HIGH] GHSA-xfhg-qx7p-6gx5: Multiple integer overflows in the evbuffer API in Libevent 2
Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_prepend, (3) evbuffer_expand, (4) exbuffer_reserve_space, or (5) evbuffer_read function, which triggers a heap-based buffer overflow or an infinite loop. NOTE: this identifier was SPLIT from CVE-2014-6272 per ADT3 due to different affected versions.
GHSA
GHSA-246p-m32j-f38r: Multiple integer overflows in the evbuffer API in Libevent 1
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2014-6272 [HIGH] GHSA-246p-m32j-f38r: Multiple integer overflows in the evbuffer API in Libevent 1
Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_expand, or (3) bufferevent_write function, which triggers a heap-based buffer overflow or an infinite loop. NOTE: this identifier has been SPLIT per ADT3 due to different affected versions. See CVE-2015-6525 for the functions that are only affected in 2.0 and later.
OSV
CVE-2015-6525: Multiple integer overflows in the evbuffer API in Libevent 2
osv·2015-08-24·CVSS 7.5
CVE-2015-6525 [HIGH] CVE-2015-6525: Multiple integer overflows in the evbuffer API in Libevent 2
Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_prepend, (3) evbuffer_expand, (4) exbuffer_reserve_space, or (5) evbuffer_read function, which triggers a heap-based buffer overflow or an infinite loop. NOTE: this identifier was SPLIT from CVE-2014-6272 per ADT3 due to different affected versions.
OSV
CVE-2014-6272: Multiple integer overflows in the evbuffer API in Libevent 1
osv·2015-08-24·CVSS 7.5
CVE-2014-6272 [HIGH] CVE-2014-6272: Multiple integer overflows in the evbuffer API in Libevent 1
Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_expand, or (3) bufferevent_write function, which triggers a heap-based buffer overflow or an infinite loop. NOTE: this identifier has been SPLIT per ADT3 due to different affected versions. See CVE-2015-6525 for the functions that are only affected in 2.0 and later.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-6525 libevent: Multiple integer overflows in the evbuffer API [fedora-all]
bugzilla·2015-08-25·CVSS 7.5
CVE-2015-6525 [HIGH] CVE-2015-6525 libevent: Multiple integer overflows in the evbuffer API [fedora-all]
CVE-2015-6525 libevent: Multiple integer overflows in the evbuffer API [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
Bugzilla
CVE-2015-6525 libevent: multiple integer overflows in the evbuffer APIs
bugzilla·2015-08-25·CVSS 7.5
CVE-2015-6525 [HIGH] CVE-2015-6525 libevent: multiple integer overflows in the evbuffer APIs
CVE-2015-6525 libevent: multiple integer overflows in the evbuffer APIs
Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the:
(1) evbuffer_add,
(2) evbuffer_prepend,
(3) evbuffer_expand,
(4) exbuffer_reserve_space, or
(5) evbuffer_read function,
which triggers a heap-based buffer overflow or an infinite loop.
NOTE: this identifier was SPLIT from CVE-2014-6272 per ADT3 due to different affected versions.
References:
http://archives.seul.org/libevent/users/Jan-2015/msg00010.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6525
Discussion:
Created libevent tracking bugs for this issu
Bugzilla
CVE-2014-6272 CVE-2015-6525 libevent: potential heap overflow in buffer/bufferevent APIs [fedora-all]
bugzilla·2015-01-05·CVSS 7.5
CVE-2014-6272 [HIGH] CVE-2014-6272 CVE-2015-6525 libevent: potential heap overflow in buffer/bufferevent APIs [fedora-all]
CVE-2014-6272 CVE-2015-6525 libevent: potential heap overflow in buffer/bufferevent APIs [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
2015-08-24
Published