CVE-2016-10196

Published

Severity

CVSS v3:
7.5 HIGH
CVSS v2:
5 MEDIUM

Description

Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (segmentation fault) via vectors involving a long string in brackets in the ip_as_string argument.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*n/an/a8.0
cpe:2.3:a:libevent_project:libevent:*:*:*:*:*:*:*:*n/a2.1.5 (including)*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*n/a52.1.0*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*n/a53.0*
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*n/a45.9.0*
cpe:2.3:a:mozilla:firefox_esr:52.0:*:*:*:*:*:*:*n/an/a52.0

External Links