CVE-2016-10196
published 2017-03-15CVE-2016-10196: Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows attackers to cause a denial of service…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
5.21%
91.6th percentile
Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (segmentation fault) via vectors involving a long string in brackets in the ip_as_string argument.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libevent | < libevent 2.0.21-stable-3 (bookworm) | libevent 2.0.21-stable-3 (bookworm) |
| libevent_project | libevent | <= 2.1.5 | — |
| libevent_project | libevent | >= 0 < 2.0.21-stable-3 | 2.0.21-stable-3 |
| libevent_project | libevent | >= 0 < 2.0.21-stable-3 | 2.0.21-stable-3 |
| libevent_project | libevent | >= 0 < 2.0.21-stable-3 | 2.0.21-stable-3 |
| libevent_project | libevent | >= 0 < 2.0.21-stable-3 | 2.0.21-stable-3 |
| mozilla | firefox | < 45.9.0 | 45.9.0 |
| mozilla | firefox | < 53.0 | 53.0 |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 52.1.0 | 52.1.0 |
| mozilla | thunderbird | >= 0 < 1:52.1.1+build1-0ubuntu0.14.04.1 | 1:52.1.1+build1-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:52.1.1+build1-0ubuntu0.16.04.1 | 1:52.1.1+build1-0ubuntu0.16.04.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2017-05-16·CVSS 9.8
CVE-2017-5429 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to read uninitialized memory, cause a denial of
service via application crash, or execute arbitrary code. (CVE-2017-5429,
CVE-2017-5430, CVE-2017-5436, CVE-2017-5443, CVE-2017-5444, CVE-2017-5445,
CVE-2017-5446, CVE-2017-5447, CVE-2017-5461, CVE-2017-5467)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to spoof the addressbar
contents, conduct cross-site scripting (XSS) attacks, cause a den
Red Hat
Mozilla: Vulnerabilities in libevent library (MFSA 2017-11, MFSA 2017-12)
vendor_redhat·2017-04-19·CVSS 9.8
CVE-2017-5437 [CRITICAL] Mozilla: Vulnerabilities in libevent library (MFSA 2017-11, MFSA 2017-12)
Mozilla: Vulnerabilities in libevent library (MFSA 2017-11, MFSA 2017-12)
No description is available for this CVE.
Statement: This CVE was found to be a duplicate, details from Mozilla project are given below:
Three vulnerabilities were reported in the Libevent library that allow for out-of-bounds reads and denial of service (DoS) attacks. These were fixed in the Libevent library and these changes were ported to Mozilla code.
These issues use CVE ids: CVE-2016-10195, CVE-2016-10196 and CVE-2016-10197
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterpri
Ubuntu
libevent vulnerabilities
vendor_ubuntu·2017-03-13
CVE-2016-10195 libevent vulnerabilities
Title: libevent vulnerabilities
Summary: Several security issues were fixed in libevent.
Guido Vranken discovered that libevent incorrectly handled memory when
processing certain data. A remote attacker could possibly use this issue
with an application that uses libevent to cause a denial of service, or
possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libevent: Stack-buffer overflow in evutil_parse_sockaddr_port()
vendor_redhat·2016-01-27·CVSS 7.5
CVE-2016-10196 [HIGH] CWE-121 libevent: Stack-buffer overflow in evutil_parse_sockaddr_port()
libevent: Stack-buffer overflow in evutil_parse_sockaddr_port()
Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (segmentation fault) via vectors involving a long string in brackets in the ip_as_string argument.
A vulnerability was found in libevent with the parsing of IPv6 addresses. If an attacker could cause an application using libevent to parse a malformed address in IPv6 notation of more than 2GiB in length, a stack overflow would occur leading to a crash.
Package: firefox (Red Hat Enterprise Linux 5) - Will not fix
Package: libevent (Red Hat Enterprise Linux 5) - Not affected
Package: nfs-utils (Red Hat Enterprise Linux 5) - Not affected
Package: openmpi (Red Hat Enter
Debian
CVE-2016-10196: libevent - Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil...
vendor_debian·2016·CVSS 7.5
CVE-2016-10196 [HIGH] CVE-2016-10196: libevent - Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil...
Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (segmentation fault) via vectors involving a long string in brackets in the ip_as_string argument.
Scope: local
bookworm: resolved (fixed in 2.0.21-stable-3)
bullseye: resolved (fixed in 2.0.21-stable-3)
forky: resolved (fixed in 2.0.21-stable-3)
sid: resolved (fixed in 2.0.21-stable-3)
trixie: resolved (fixed in 2.0.21-stable-3)
GHSA
GHSA-c3jf-437c-9298: Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil
ghsa_unreviewed·2022-05-13
CVE-2016-10196 [HIGH] CWE-787 GHSA-c3jf-437c-9298: Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil
Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (segmentation fault) via vectors involving a long string in brackets in the ip_as_string argument.
OSV
thunderbird vulnerabilities
osv·2017-05-16·CVSS 9.8
CVE-2017-5429 [CRITICAL] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to read uninitialized memory, cause a denial of
service via application crash, or execute arbitrary code. (CVE-2017-5429,
CVE-2017-5430, CVE-2017-5436, CVE-2017-5443, CVE-2017-5444, CVE-2017-5445,
CVE-2017-5446, CVE-2017-5447, CVE-2017-5461, CVE-2017-5467)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to spoof the addressbar
contents, conduct cross-site scripting (XSS) attacks, cause a denial of
service via application crash, or execute arbitrary code. (CV
OSV
CVE-2016-10196: Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil
osv·2017-03-15·CVSS 7.5
CVE-2016-10196 [HIGH] CVE-2016-10196: Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil
Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (segmentation fault) via vectors involving a long string in brackets in the ip_as_string argument.
No detection rules found.
No public exploits indexed.
Bugzilla
3 public security flaws in libevent, which may affect mozilla products
bugzilla·2017-03-01·CVSS 9.8
[CRITICAL] 3 public security flaws in libevent, which may affect mozilla products
3 public security flaws in libevent, which may affect mozilla products
User Agent: Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:50.0) Gecko/20100101 Firefox/50.0
Build ID: 20161130084355
Steps to reproduce:
Vulnerable code here is present in libevent embedded in firefox, thunderbird, xulrunner - part of the Chromium IPC code, which seems to be used for internal IPC between mozilla processes.
Previously https://www.mozilla.org/en-US/security/advisories/mfsa2015-57/ concerned Chromium IPC, and it looks like in fixing that you ensured IPC peers are authenticated. Thus any compromise could only be through causing an IPC peer to send a dangerous message, which would force a hostname, IPv6 address or DNS packet to be parsed by libevent code from attacker-controlled input.
In decreasing order
Bugzilla
CVE-2016-10195 CVE-2016-10196 CVE-2016-10197 libevent: various flaws [fedora-all]
bugzilla·2017-02-02·CVSS 9.8
CVE-2016-10195 [CRITICAL] CVE-2016-10195 CVE-2016-10196 CVE-2016-10197 libevent: various flaws [fedora-all]
CVE-2016-10195 CVE-2016-10196 CVE-2016-10197 libevent: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
Bugzilla
CVE-2016-10196 libevent: Stack-buffer overflow in evutil_parse_sockaddr_port()
bugzilla·2017-02-02·CVSS 7.5
CVE-2016-10196 [HIGH] CVE-2016-10196 libevent: Stack-buffer overflow in evutil_parse_sockaddr_port()
CVE-2016-10196 libevent: Stack-buffer overflow in evutil_parse_sockaddr_port()
A vulnerability was found in libevent. There is a stack-buffer overflow in evutil.c.
Upstream bug:
https://github.com/libevent/libevent/issues/318
Upstream patch:
https://github.com/libevent/libevent/commit/329acc18a0768c21ba22522f01a5c7f46cacc4d5
Discussion:
Created libevent tracking bugs for this issue:
Affects: fedora-all [bug 1418616]
---
nfs-utils since rhel-5 does not use embedded libevent
---
libevent.1.4 does not include support for IPv6.
openmpi does not use or expose any functions in libevent which expose this vulnerability.
Stack canaries prevent exploitation of this flaw for arbitrary code execution, limiting the potential impact to only a crash.
---
This issue has been addressed in t
http://www.debian.org/security/2017/dsa-3789http://www.openwall.com/lists/oss-security/2017/01/31/17http://www.openwall.com/lists/oss-security/2017/02/02/7http://www.securityfocus.com/bid/96014http://www.securitytracker.com/id/1038320https://access.redhat.com/errata/RHSA-2017:1104https://access.redhat.com/errata/RHSA-2017:1106https://access.redhat.com/errata/RHSA-2017:1201https://bugzilla.mozilla.org/show_bug.cgi?id=1343453https://github.com/libevent/libevent/blob/release-2.1.6-beta/ChangeLoghttps://github.com/libevent/libevent/commit/329acc18a0768c21ba22522f01a5c7f46cacc4d5https://github.com/libevent/libevent/issues/318https://security.gentoo.org/glsa/201705-01https://www.mozilla.org/security/advisories/mfsa2017-10/https://www.mozilla.org/security/advisories/mfsa2017-11/https://www.mozilla.org/security/advisories/mfsa2017-12/https://www.mozilla.org/security/advisories/mfsa2017-13/http://www.debian.org/security/2017/dsa-3789http://www.openwall.com/lists/oss-security/2017/01/31/17http://www.openwall.com/lists/oss-security/2017/02/02/7http://www.securityfocus.com/bid/96014http://www.securitytracker.com/id/1038320https://access.redhat.com/errata/RHSA-2017:1104https://access.redhat.com/errata/RHSA-2017:1106https://access.redhat.com/errata/RHSA-2017:1201https://bugzilla.mozilla.org/show_bug.cgi?id=1343453https://github.com/libevent/libevent/blob/release-2.1.6-beta/ChangeLoghttps://github.com/libevent/libevent/commit/329acc18a0768c21ba22522f01a5c7f46cacc4d5https://github.com/libevent/libevent/issues/318https://security.gentoo.org/glsa/201705-01https://www.mozilla.org/security/advisories/mfsa2017-10/https://www.mozilla.org/security/advisories/mfsa2017-11/https://www.mozilla.org/security/advisories/mfsa2017-12/https://www.mozilla.org/security/advisories/mfsa2017-13/
2017-03-15
Published