REDHAT-BUG-1418612: Low severity libevent libevent vulnerability
A vulnerability was found in libevent. There is an out-of-bounds read in the DNS code of Libevent.
Upstream bug:
https://github.com/libevent/libevent/issues/332
Upstream patch:
https://github.com/libevent/libevent/commit/ec65c42052d95d2c23d1d837136d1cf1d9ecef9e
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1418612?
The severity of REDHAT-BUG-1418612 is categorized as moderate due to the potential for an out-of-bounds read vulnerability.
How do I fix REDHAT-BUG-1418612?
To fix REDHAT-BUG-1418612, you should apply the latest patch provided by the upstream maintainers of Libevent.
Which versions of Libevent are affected by REDHAT-BUG-1418612?
All versions of Libevent that are prior to the implementation of the fix for the out-of-bounds read in the DNS code are potentially affected by REDHAT-BUG-1418612.
What impact does REDHAT-BUG-1418612 have on systems using Libevent?
REDHAT-BUG-1418612 can lead to potential information disclosure or application crashes due to the out-of-bounds read in the DNS handling code.
Is there a known exploit for REDHAT-BUG-1418612?
As of now, there are no public exploits known for REDHAT-BUG-1418612, but the vulnerability could be leveraged by attackers if not mitigated.