CVE-2015-6525: Buffer Overflow
Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbufferadd, (2) evbufferprepend, (3) evbufferexpand, (4) exbufferreservespace, or (5) evbufferread function, which triggers a heap-based buffer overflow or an infinite loop. NOTE: this identifier was SPLIT from CVE-2014-6272 per ADT3 due to different affected versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6525?
CVE-2015-6525 is considered to have a high severity due to potential denial of service vulnerabilities.
How do I fix CVE-2015-6525?
To fix CVE-2015-6525, upgrade to Libevent version 2.0.22 or 2.1.5-beta or later.
Which software is affected by CVE-2015-6525?
CVE-2015-6525 affects all versions of Libevent prior to 2.0.22 and 2.1.5-beta.
What types of attacks can CVE-2015-6525 facilitate?
CVE-2015-6525 can enable context-dependent attackers to cause denial of service attacks.
Is CVE-2015-6525 exploit-related to input sizes?
Yes, CVE-2015-6525 is associated with vulnerabilities triggered by excessively large inputs.