CVE-2016-10197
published 2017-03-15CVE-2016-10197: The search_make_new function in evdns.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (out-of-bounds read) via an empty hostname.
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
5.19%
91.5th percentile
The search_make_new function in evdns.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (out-of-bounds read) via an empty hostname.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libevent | < libevent 2.0.21-stable-3 (bookworm) | libevent 2.0.21-stable-3 (bookworm) |
| libevent_project | libevent | <= 2.1.5 | — |
| libevent_project | libevent | >= 0 < 2.0.21-stable-3 | 2.0.21-stable-3 |
| libevent_project | libevent | >= 0 < 2.0.21-stable-3 | 2.0.21-stable-3 |
| libevent_project | libevent | >= 0 < 2.0.21-stable-3 | 2.0.21-stable-3 |
| libevent_project | libevent | >= 0 < 2.0.21-stable-3 | 2.0.21-stable-3 |
| mozilla | thunderbird | >= 0 < 1:52.1.1+build1-0ubuntu0.14.04.1 | 1:52.1.1+build1-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:52.1.1+build1-0ubuntu0.16.04.1 | 1:52.1.1+build1-0ubuntu0.16.04.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2017-05-16·CVSS 9.8
CVE-2017-5429 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to read uninitialized memory, cause a denial of
service via application crash, or execute arbitrary code. (CVE-2017-5429,
CVE-2017-5430, CVE-2017-5436, CVE-2017-5443, CVE-2017-5444, CVE-2017-5445,
CVE-2017-5446, CVE-2017-5447, CVE-2017-5461, CVE-2017-5467)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to spoof the addressbar
contents, conduct cross-site scripting (XSS) attacks, cause a den
Red Hat
Mozilla: Vulnerabilities in libevent library (MFSA 2017-11, MFSA 2017-12)
vendor_redhat·2017-04-19·CVSS 9.8
CVE-2017-5437 [CRITICAL] Mozilla: Vulnerabilities in libevent library (MFSA 2017-11, MFSA 2017-12)
Mozilla: Vulnerabilities in libevent library (MFSA 2017-11, MFSA 2017-12)
No description is available for this CVE.
Statement: This CVE was found to be a duplicate, details from Mozilla project are given below:
Three vulnerabilities were reported in the Libevent library that allow for out-of-bounds reads and denial of service (DoS) attacks. These were fixed in the Libevent library and these changes were ported to Mozilla code.
These issues use CVE ids: CVE-2016-10195, CVE-2016-10196 and CVE-2016-10197
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterpri
Ubuntu
libevent vulnerabilities
vendor_ubuntu·2017-03-13
CVE-2016-10195 libevent vulnerabilities
Title: libevent vulnerabilities
Summary: Several security issues were fixed in libevent.
Guido Vranken discovered that libevent incorrectly handled memory when
processing certain data. A remote attacker could possibly use this issue
with an application that uses libevent to cause a denial of service, or
possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libevent: Out-of-bounds read in search_make_new()
vendor_redhat·2016-03-03·CVSS 7.5
CVE-2016-10197 [HIGH] CWE-125 libevent: Out-of-bounds read in search_make_new()
libevent: Out-of-bounds read in search_make_new()
The search_make_new function in evdns.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (out-of-bounds read) via an empty hostname.
An out of bounds read vulnerability was found in libevent in the search_make_new function. If an attacker could cause an application using libevent to attempt resolving an empty hostname, an out of bounds read could occur possibly leading to a crash.
Package: firefox (Red Hat Enterprise Linux 5) - Will not fix
Package: libevent (Red Hat Enterprise Linux 5) - Will not fix
Package: nfs-utils (Red Hat Enterprise Linux 5) - Not affected
Package: openmpi (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Will not fix
Package: chromium-b
Debian
CVE-2016-10197: libevent - The search_make_new function in evdns.c in libevent before 2.1.6-beta allows att...
vendor_debian·2016·CVSS 7.5
CVE-2016-10197 [HIGH] CVE-2016-10197: libevent - The search_make_new function in evdns.c in libevent before 2.1.6-beta allows att...
The search_make_new function in evdns.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (out-of-bounds read) via an empty hostname.
Scope: local
bookworm: resolved (fixed in 2.0.21-stable-3)
bullseye: resolved (fixed in 2.0.21-stable-3)
forky: resolved (fixed in 2.0.21-stable-3)
sid: resolved (fixed in 2.0.21-stable-3)
trixie: resolved (fixed in 2.0.21-stable-3)
GHSA
GHSA-p9p6-m8vm-vcxx: The search_make_new function in evdns
ghsa_unreviewed·2022-05-13
CVE-2016-10197 [HIGH] CWE-125 GHSA-p9p6-m8vm-vcxx: The search_make_new function in evdns
The search_make_new function in evdns.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (out-of-bounds read) via an empty hostname.
OSV
thunderbird vulnerabilities
osv·2017-05-16·CVSS 9.8
CVE-2017-5429 [CRITICAL] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to read uninitialized memory, cause a denial of
service via application crash, or execute arbitrary code. (CVE-2017-5429,
CVE-2017-5430, CVE-2017-5436, CVE-2017-5443, CVE-2017-5444, CVE-2017-5445,
CVE-2017-5446, CVE-2017-5447, CVE-2017-5461, CVE-2017-5467)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to spoof the addressbar
contents, conduct cross-site scripting (XSS) attacks, cause a denial of
service via application crash, or execute arbitrary code. (CV
OSV
CVE-2016-10197: The search_make_new function in evdns
osv·2017-03-15·CVSS 7.5
CVE-2016-10197 [HIGH] CVE-2016-10197: The search_make_new function in evdns
The search_make_new function in evdns.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (out-of-bounds read) via an empty hostname.
No detection rules found.
No public exploits indexed.
Bugzilla
3 public security flaws in libevent, which may affect mozilla products
bugzilla·2017-03-01·CVSS 9.8
[CRITICAL] 3 public security flaws in libevent, which may affect mozilla products
3 public security flaws in libevent, which may affect mozilla products
User Agent: Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:50.0) Gecko/20100101 Firefox/50.0
Build ID: 20161130084355
Steps to reproduce:
Vulnerable code here is present in libevent embedded in firefox, thunderbird, xulrunner - part of the Chromium IPC code, which seems to be used for internal IPC between mozilla processes.
Previously https://www.mozilla.org/en-US/security/advisories/mfsa2015-57/ concerned Chromium IPC, and it looks like in fixing that you ensured IPC peers are authenticated. Thus any compromise could only be through causing an IPC peer to send a dangerous message, which would force a hostname, IPv6 address or DNS packet to be parsed by libevent code from attacker-controlled input.
In decreasing order
Bugzilla
CVE-2016-10197 libevent: Out-of-bounds read in search_make_new()
bugzilla·2017-02-02·CVSS 7.5
CVE-2016-10197 [HIGH] CVE-2016-10197 libevent: Out-of-bounds read in search_make_new()
CVE-2016-10197 libevent: Out-of-bounds read in search_make_new()
A vulnerability was found in libevent. There is an out-of-bounds read in the DNS code of Libevent.
Upstream bug:
https://github.com/libevent/libevent/issues/332
Upstream patch:
https://github.com/libevent/libevent/commit/ec65c42052d95d2c23d1d837136d1cf1d9ecef9e
Discussion:
Created libevent tracking bugs for this issue:
Affects: fedora-all [bug 1418616]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:1201 https://access.redhat.com/errata/RHSA-2017:1201
Bugzilla
CVE-2016-10195 CVE-2016-10196 CVE-2016-10197 libevent: various flaws [fedora-all]
bugzilla·2017-02-02·CVSS 9.8
CVE-2016-10195 [CRITICAL] CVE-2016-10195 CVE-2016-10196 CVE-2016-10197 libevent: various flaws [fedora-all]
CVE-2016-10195 CVE-2016-10196 CVE-2016-10197 libevent: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
http://www.debian.org/security/2017/dsa-3789http://www.openwall.com/lists/oss-security/2017/01/31/17http://www.openwall.com/lists/oss-security/2017/02/02/7http://www.securityfocus.com/bid/96014http://www.securitytracker.com/id/1038320https://access.redhat.com/errata/RHSA-2017:1104https://access.redhat.com/errata/RHSA-2017:1106https://access.redhat.com/errata/RHSA-2017:1201https://github.com/libevent/libevent/blob/release-2.1.6-beta/ChangeLoghttps://github.com/libevent/libevent/commit/ec65c42052d95d2c23d1d837136d1cf1d9ecef9ehttps://github.com/libevent/libevent/issues/332https://security.gentoo.org/glsa/201705-01http://www.debian.org/security/2017/dsa-3789http://www.openwall.com/lists/oss-security/2017/01/31/17http://www.openwall.com/lists/oss-security/2017/02/02/7http://www.securityfocus.com/bid/96014http://www.securitytracker.com/id/1038320https://access.redhat.com/errata/RHSA-2017:1104https://access.redhat.com/errata/RHSA-2017:1106https://access.redhat.com/errata/RHSA-2017:1201https://github.com/libevent/libevent/blob/release-2.1.6-beta/ChangeLoghttps://github.com/libevent/libevent/commit/ec65c42052d95d2c23d1d837136d1cf1d9ecef9ehttps://github.com/libevent/libevent/issues/332https://security.gentoo.org/glsa/201705-01
2017-03-15
Published