Candidate: CVE-2015-6525 PublicDate: 2015-08-24 14:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6525 http://www.debian.org/security/2015/dsa-3119 http://archives.seul.org/libevent/users/Jan-2015/msg00010.html https://ubuntu.com/security/notices/USN-2477-1 Description: Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_prepend, (3) evbuffer_expand, (4) exbuffer_reserve_space, or (5) evbuffer_read function, which triggers a heap-based buffer overflow or an infinite loop. NOTE: this identifier was SPLIT from CVE-2014-6272 per ADT3 due to different affected versions. Ubuntu-Description: Notes: mdeslaur> CVE was split from CVE-2014-6272, but fixes were already applied mdeslaur> in usn-2477-1 Bugs: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774645 Priority: medium Discovered-by: Andrew Bartlett Assigned-to: CVSS: Patches_libevent: upstream: https://github.com/libevent/libevent/commit/7b21c4eabf1f3946d3f63cce1319c490caab8ecf (1.4) upstream: https://github.com/libevent/libevent/commit/20d6d4458bee5d88bda1511c225c25b2d3198d6c (2.0) upstream: https://github.com/libevent/libevent/commit/841ecbd96105c84ac2e7c9594aeadbcc6fb38bc4 (2.1) upstream_libevent: released (1.4.15-stable, 2.0.22-stable, 2.1.5-beta) precise_libevent: released (2.0.16-stable-1ubuntu0.1) trusty_libevent: released (2.0.21-stable-1ubuntu1.14.04.1) trusty/esm_libevent: released (2.0.21-stable-1ubuntu1.14.04.1) vivid_libevent: not-affected (2.0.21-stable-2) devel_libevent: not-affected (2.0.21-stable-2)