CVE-2016-10195
published 2017-03-15CVE-2016-10195: The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_len…
PriorityP348critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.68%
93.1th percentile
The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_len variable, which triggers an out-of-bounds stack read.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libevent | < libevent 2.0.21-stable-3 (bookworm) | libevent 2.0.21-stable-3 (bookworm) |
| libevent_project | libevent | <= 2.1.5 | — |
| libevent_project | libevent | >= 0 < 2.0.21-stable-3 | 2.0.21-stable-3 |
| libevent_project | libevent | >= 0 < 2.0.21-stable-3 | 2.0.21-stable-3 |
| libevent_project | libevent | >= 0 < 2.0.21-stable-3 | 2.0.21-stable-3 |
| libevent_project | libevent | >= 0 < 2.0.21-stable-3 | 2.0.21-stable-3 |
| mozilla | thunderbird | >= 0 < 1:52.1.1+build1-0ubuntu0.14.04.1 | 1:52.1.1+build1-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:52.1.1+build1-0ubuntu0.16.04.1 | 1:52.1.1+build1-0ubuntu0.16.04.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2017-05-16·CVSS 9.8
CVE-2017-5429 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to read uninitialized memory, cause a denial of
service via application crash, or execute arbitrary code. (CVE-2017-5429,
CVE-2017-5430, CVE-2017-5436, CVE-2017-5443, CVE-2017-5444, CVE-2017-5445,
CVE-2017-5446, CVE-2017-5447, CVE-2017-5461, CVE-2017-5467)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to spoof the addressbar
contents, conduct cross-site scripting (XSS) attacks, cause a den
Red Hat
Mozilla: Vulnerabilities in libevent library (MFSA 2017-11, MFSA 2017-12)
vendor_redhat·2017-04-19·CVSS 9.8
CVE-2017-5437 [CRITICAL] Mozilla: Vulnerabilities in libevent library (MFSA 2017-11, MFSA 2017-12)
Mozilla: Vulnerabilities in libevent library (MFSA 2017-11, MFSA 2017-12)
No description is available for this CVE.
Statement: This CVE was found to be a duplicate, details from Mozilla project are given below:
Three vulnerabilities were reported in the Libevent library that allow for out-of-bounds reads and denial of service (DoS) attacks. These were fixed in the Libevent library and these changes were ported to Mozilla code.
These issues use CVE ids: CVE-2016-10195, CVE-2016-10196 and CVE-2016-10197
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterpri
Ubuntu
libevent vulnerabilities
vendor_ubuntu·2017-03-13
CVE-2016-10195 libevent vulnerabilities
Title: libevent vulnerabilities
Summary: Several security issues were fixed in libevent.
Guido Vranken discovered that libevent incorrectly handled memory when
processing certain data. A remote attacker could possibly use this issue
with an application that uses libevent to cause a denial of service, or
possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libevent: Stack-buffer overflow in the name_parse() function
vendor_redhat·2016-01-27·CVSS 9.8
CVE-2016-10195 [CRITICAL] CWE-125 libevent: Stack-buffer overflow in the name_parse() function
libevent: Stack-buffer overflow in the name_parse() function
The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_len variable, which triggers an out-of-bounds stack read.
A vulnerability was found in libevent with the parsing of DNS requests and replies. An attacker could send a forged DNS response to an application using libevent which could lead to reading data out of bounds on the heap, potentially disclosing a small amount of application memory.
Package: firefox (Red Hat Enterprise Linux 5) - Will not fix
Package: libevent (Red Hat Enterprise Linux 5) - Will not fix
Package: nfs-utils (Red Hat Enterprise Linux 5) - Not affected
Package: openmpi (Red Hat Enterprise Linux 5) - Not affect
Debian
CVE-2016-10195: libevent - The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote a...
vendor_debian·2016·CVSS 9.8
CVE-2016-10195 [CRITICAL] CVE-2016-10195: libevent - The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote a...
The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_len variable, which triggers an out-of-bounds stack read.
Scope: local
bookworm: resolved (fixed in 2.0.21-stable-3)
bullseye: resolved (fixed in 2.0.21-stable-3)
forky: resolved (fixed in 2.0.21-stable-3)
sid: resolved (fixed in 2.0.21-stable-3)
trixie: resolved (fixed in 2.0.21-stable-3)
GHSA
GHSA-3x9p-6xxq-5rhj: The name_parse function in evdns
ghsa_unreviewed·2022-05-13
CVE-2016-10195 [CRITICAL] CWE-125 GHSA-3x9p-6xxq-5rhj: The name_parse function in evdns
The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_len variable, which triggers an out-of-bounds stack read.
OSV
thunderbird vulnerabilities
osv·2017-05-16·CVSS 9.8
CVE-2017-5429 [CRITICAL] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to read uninitialized memory, cause a denial of
service via application crash, or execute arbitrary code. (CVE-2017-5429,
CVE-2017-5430, CVE-2017-5436, CVE-2017-5443, CVE-2017-5444, CVE-2017-5445,
CVE-2017-5446, CVE-2017-5447, CVE-2017-5461, CVE-2017-5467)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to spoof the addressbar
contents, conduct cross-site scripting (XSS) attacks, cause a denial of
service via application crash, or execute arbitrary code. (CV
OSV
CVE-2016-10195: The name_parse function in evdns
osv·2017-03-15·CVSS 9.8
CVE-2016-10195 [CRITICAL] CVE-2016-10195: The name_parse function in evdns
The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_len variable, which triggers an out-of-bounds stack read.
No detection rules found.
No public exploits indexed.
Bugzilla
3 public security flaws in libevent, which may affect mozilla products
bugzilla·2017-03-01·CVSS 9.8
[CRITICAL] 3 public security flaws in libevent, which may affect mozilla products
3 public security flaws in libevent, which may affect mozilla products
User Agent: Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:50.0) Gecko/20100101 Firefox/50.0
Build ID: 20161130084355
Steps to reproduce:
Vulnerable code here is present in libevent embedded in firefox, thunderbird, xulrunner - part of the Chromium IPC code, which seems to be used for internal IPC between mozilla processes.
Previously https://www.mozilla.org/en-US/security/advisories/mfsa2015-57/ concerned Chromium IPC, and it looks like in fixing that you ensured IPC peers are authenticated. Thus any compromise could only be through causing an IPC peer to send a dangerous message, which would force a hostname, IPv6 address or DNS packet to be parsed by libevent code from attacker-controlled input.
In decreasing order
Bugzilla
CVE-2016-10195 libevent: Stack-buffer overflow in the name_parse() function
bugzilla·2017-02-02·CVSS 9.8
CVE-2016-10195 [CRITICAL] CVE-2016-10195 libevent: Stack-buffer overflow in the name_parse() function
CVE-2016-10195 libevent: Stack-buffer overflow in the name_parse() function
A vulnerability was found in libevent. The name_parse() function in libevent's DNS code is vulnerable to a buffer overread.
Upstream bug:
https://github.com/libevent/libevent/issues/317
Upstream patch:
https://github.com/libevent/libevent/commit/96f64a022014a208105ead6c8a7066018449d86d
Discussion:
Created libevent tracking bugs for this issue:
Affects: fedora-all [bug 1418616]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:1201 https://access.redhat.com/errata/RHSA-2017:1201
Bugzilla
CVE-2016-10195 CVE-2016-10196 CVE-2016-10197 libevent: various flaws [fedora-all]
bugzilla·2017-02-02·CVSS 9.8
CVE-2016-10195 [CRITICAL] CVE-2016-10195 CVE-2016-10196 CVE-2016-10197 libevent: various flaws [fedora-all]
CVE-2016-10195 CVE-2016-10196 CVE-2016-10197 libevent: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
http://www.debian.org/security/2017/dsa-3789http://www.openwall.com/lists/oss-security/2017/01/31/17http://www.openwall.com/lists/oss-security/2017/02/02/7http://www.securityfocus.com/bid/96014http://www.securitytracker.com/id/1038320https://access.redhat.com/errata/RHSA-2017:1104https://access.redhat.com/errata/RHSA-2017:1106https://access.redhat.com/errata/RHSA-2017:1201https://github.com/libevent/libevent/blob/release-2.1.6-beta/ChangeLoghttps://github.com/libevent/libevent/commit/96f64a022014a208105ead6c8a7066018449d86dhttps://github.com/libevent/libevent/issues/317https://security.gentoo.org/glsa/201705-01http://www.debian.org/security/2017/dsa-3789http://www.openwall.com/lists/oss-security/2017/01/31/17http://www.openwall.com/lists/oss-security/2017/02/02/7http://www.securityfocus.com/bid/96014http://www.securitytracker.com/id/1038320https://access.redhat.com/errata/RHSA-2017:1104https://access.redhat.com/errata/RHSA-2017:1106https://access.redhat.com/errata/RHSA-2017:1201https://github.com/libevent/libevent/blob/release-2.1.6-beta/ChangeLoghttps://github.com/libevent/libevent/commit/96f64a022014a208105ead6c8a7066018449d86dhttps://github.com/libevent/libevent/issues/317https://security.gentoo.org/glsa/201705-01
2017-03-15
Published