Univention Bugzilla – Bug 43552
libevent: Multiple issues (4.1)
Last modified: 2017-02-22 12:33:03 CET
Upstream Debian package version 2.0.19-stable-3+deb7u2 fixes these issues: * Stack-buffer overflow in the name_parse() function (CVE-2016-10195) * Stack-buffer overflow in evutil_parse_sockaddr_port() (CVE-2016-10196) * Out-of-bounds read in search_make_new() (CVE-2016-10197)
Imported and built. Advisory: libevent.yaml
OK: advisory OK: version dtroeder@dimma:~$ repo_stat.py libevent [..] Version 2.0.19-stable-3+deb7u2 Rev 82812 Date 2017-02-15 20:45:50 Release 4.1-0-0 Scope errata4.1-4 https://security-tracker.debian.org/tracker/source-package/libevent Release Version wheezy 2.0.19-stable-3+deb7u1 wheezy (security) 2.0.19-stable-3+deb7u2 --- Bug wheezy jessie stretch sid Description CVE-2016-10197 fixed fixed vulnerable fixed CVE-2016-10196 fixed fixed vulnerable fixed CVE-2016-10195 fixed fixed vulnerable fixed OK: manual test: root@m90s4:~# univention-install libevent-dev root@m90s4:~# wget https://github.com/libevent/libevent/raw/master/sample/hello-world.c root@m90s4:~# gcc -o libevent-hello-world -levent /usr/share/doc/libevent-dev/examples/hello-world.c root@m90s4:~# ./libevent-hello-world root@m90s4:~# [ 'Hello, World!' = "$(ncat 127.0.0.1 9995)" ] && echo OK OK
Actually /usr/share/doc/libevent-dev/examples/hello-world.c was used, not the one from github.
<http://errata.software-univention.de/ucs/4.1/404.html>