CVE-2016-10195: Critical severity red hat libevent vulnerability
A vulnerability was found in libevent. The nameparse() function in libevent's DNS code is vulnerable to a buffer overread.
Upstream bug:
https://github.com/libevent/libevent/issues/317
Upstream patch:
https://github.com/libevent/libevent/commit/96f64a022014a208105ead6c8a7066018449d86d
Other sources
The nameparse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the labellen variable, which triggers an out-of-bounds stack read.
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10195?
CVE-2016-10195 is considered to have a medium severity due to its potential for buffer overread, which can lead to information disclosure.
How do I fix CVE-2016-10195?
To fix CVE-2016-10195, upgrade libevent to version 2.1.12-stable-10 or later.
Which versions of libevent are affected by CVE-2016-10195?
CVE-2016-10195 affects libevent versions up to and including 2.1.5.
What is the nature of the vulnerability in CVE-2016-10195?
The vulnerability in CVE-2016-10195 is a buffer overread in the name_parse() function of libevent's DNS code.
Is CVE-2016-10195 specific to any operating system?
CVE-2016-10195 is notably associated with Debian-based systems and potentially affects any systems using the vulnerable versions of libevent.