REDHAT-BUG-1418608: Medium severity libevent libevent vulnerability
A vulnerability was found in libevent. The nameparse() function in libevent's DNS code is vulnerable to a buffer overread.
Upstream bug:
https://github.com/libevent/libevent/issues/317
Upstream patch:
https://github.com/libevent/libevent/commit/96f64a022014a208105ead6c8a7066018449d86d
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1418608?
The severity of REDHAT-BUG-1418608 is considered high due to the potential for a buffer overread in the DNS code.
How do I fix REDHAT-BUG-1418608?
To fix REDHAT-BUG-1418608, apply the latest patch available for the libevent library.
What is the impact of REDHAT-BUG-1418608?
The impact of REDHAT-BUG-1418608 may include exploitation of the vulnerability leading to information disclosure or denial of service.
Which versions of libevent are affected by REDHAT-BUG-1418608?
REDHAT-BUG-1418608 affects various versions of the libevent library that contain the vulnerable name_parse() function.
Is there an upstream resolution for REDHAT-BUG-1418608?
Yes, there is an upstream resolution for REDHAT-BUG-1418608, which includes a patch that addresses the buffer overread issue.