Vulnerability Bulletins

DSA-3119 libevent - security update

   
Affected software Debian
 
Andrew Bartlett of Catalyst reported a defect affecting certainapplications using the Libevent evbuffer API. This defect leavesapplications which pass insanely large inputs to evbuffers open to apossible heap overflow or infinite loop. In order to exploit this flaw,an attacker needs to be able to find a way to provoke the program intotrying to make a buffer chunk larger than what will fit into a singlesize_t or off_t.

More info:

https://www.debian.org/security/2015/dsa-3119