CVE-2016-10197: High severity debian linux vulnerability
A vulnerability was found in libevent. There is an out-of-bounds read in the DNS code of Libevent.
Upstream bug:
https://github.com/libevent/libevent/issues/332
Upstream patch:
https://github.com/libevent/libevent/commit/ec65c42052d95d2c23d1d837136d1cf1d9ecef9e
Other sources
The searchmakenew function in evdns.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (out-of-bounds read) via an empty hostname.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10197?
CVE-2016-10197 is classified as a moderate severity vulnerability due to its potential for out-of-bounds reads.
How do I fix CVE-2016-10197?
To fix CVE-2016-10197, update libevent to version 2.1.12-stable-1 or later.
What software is affected by CVE-2016-10197?
CVE-2016-10197 affects multiple versions of the libevent library, particularly versions prior to 2.1.12-stable-1.
What type of vulnerability is CVE-2016-10197?
CVE-2016-10197 is an out-of-bounds read vulnerability found in the DNS code of libevent.
How can I identify if my system is vulnerable to CVE-2016-10197?
You can identify vulnerability to CVE-2016-10197 by checking if your version of libevent is older than 2.1.12-stable-1.