CVE-2016-10195

Published

Severity

CVSS v3:
9.8 CRITICAL
CVSS v2:
7.5 HIGH

Description

The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_len variable, which triggers an out-of-bounds stack read.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:libevent_project:libevent:*:*:*:*:*:*:*:*n/a2.1.5 (including)*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*n/an/a8.0

External Links