Vulnerability Name: CVE-2015-6525 (CCN-106188) Assigned: 2015-01-05 Published: 2015-01-05 Updated: 2015-08-26 Summary: Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_prepend, (3) evbuffer_expand, (4) exbuffer_reserve_space, or (5) evbuffer_read function, which triggers a heap-based buffer overflow or an infinite loop. Note : this identifier was SPLIT from CVE-2014-6272 per ADT3 due to different affected versions. CVSS v3 Severity: 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Low
CVSS v2 Severity: 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P )5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
1.9 Low (CCN CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P )1.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): MediumAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Partial
Vulnerability Type: CWE-189 Vulnerability Consequences: Gain Access References: Source: CCN Type: libevent Mailing List, Mon, 5 Jan 2015 10:27:49 -0500[Libevent-users] Advisory: integer overflow in evbuffers for Libevent 1.4.14b,2.0.21,2.1.4-alpha [CVE-2014-6272] Source: MLIST Type: Vendor Advisory[Libevent-users] 20150105 Advisory: integer overflow in evbuffers for Libevent <= 1.4.14b,2.0.21,2.1.4-alpha [CVE-2014-6272] Source: MITRE Type: CNACVE-2015-6525 Source: CCN Type: Libevent Web sitelibevent an event notification library Source: DEBIAN Type: UNKNOWNDSA-3119 Source: XF Type: UNKNOWNlibevent-cve20156525-dos(106188) Source: CCN Type: WhiteSource Vulnerability DatabaseCVE-2015-6525 Vulnerable Configuration: Configuration 1 :cpe:/o:debian:debian_linux:7.1:*:*:*:*:*:*:* Configuration 2 :cpe:/a:libevent_project:libevent:2.0.1:*:*:*:*:*:*:* OR cpe:/a:libevent_project:libevent:2.0.2:*:*:*:*:*:*:* OR cpe:/a:libevent_project:libevent:2.0.3:*:*:*:*:*:*:* OR cpe:/a:libevent_project:libevent:2.0.4:*:*:*:*:*:*:* OR cpe:/a:libevent_project:libevent:2.0.5:*:*:*:*:*:*:* OR cpe:/a:libevent_project:libevent:2.0.6:*:*:*:*:*:*:* OR cpe:/a:libevent_project:libevent:2.0.7:*:*:*:*:*:*:* OR cpe:/a:libevent_project:libevent:2.0.8:*:*:*:*:*:*:* OR cpe:/a:libevent_project:libevent:2.0.9:*:*:*:*:*:*:* OR cpe:/a:libevent_project:libevent:2.0.10:*:*:*:*:*:*:* OR cpe:/a:libevent_project:libevent:2.0.11:*:*:*:*:*:*:* OR cpe:/a:libevent_project:libevent:2.0.12:*:*:*:*:*:*:* OR cpe:/a:libevent_project:libevent:2.0.13:*:*:*:*:*:*:* OR cpe:/a:libevent_project:libevent:2.0.14:*:*:*:*:*:*:* OR cpe:/a:libevent_project:libevent:2.0.15:*:*:*:*:*:*:* OR cpe:/a:libevent_project:libevent:2.0.16:*:*:*:*:*:*:* OR cpe:/a:libevent_project:libevent:2.0.17:*:*:*:*:*:*:* OR cpe:/a:libevent_project:libevent:2.0.18:*:*:*:*:*:*:* OR cpe:/a:libevent_project:libevent:2.0.19:*:*:*:*:*:*:* OR cpe:/a:libevent_project:libevent:2.0.20:*:*:*:*:*:*:* OR cpe:/a:libevent_project:libevent:2.0.21:*:*:*:*:*:*:* OR cpe:/a:libevent_project:libevent:2.1.1:*:*:*:*:*:*:* OR cpe:/a:libevent_project:libevent:2.1.2:*:*:*:*:*:*:* OR cpe:/a:libevent_project:libevent:2.1.3:*:*:*:*:*:*:* OR cpe:/a:libevent_project:libevent:2.1.4:*:*:*:*:*:*:* Denotes that component is vulnerable Oval Definitions BACK
debian debian linux 7.1
libevent_project libevent 2.0.1
libevent_project libevent 2.0.2
libevent_project libevent 2.0.3
libevent_project libevent 2.0.4
libevent_project libevent 2.0.5
libevent_project libevent 2.0.6
libevent_project libevent 2.0.7
libevent_project libevent 2.0.8
libevent_project libevent 2.0.9
libevent_project libevent 2.0.10
libevent_project libevent 2.0.11
libevent_project libevent 2.0.12
libevent_project libevent 2.0.13
libevent_project libevent 2.0.14
libevent_project libevent 2.0.15
libevent_project libevent 2.0.16
libevent_project libevent 2.0.17
libevent_project libevent 2.0.18
libevent_project libevent 2.0.19
libevent_project libevent 2.0.20
libevent_project libevent 2.0.21
libevent_project libevent 2.1.1
libevent_project libevent 2.1.2
libevent_project libevent 2.1.3
libevent_project libevent 2.1.4