Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_prepend, (3) evbuffer_expand, (4) exbuffer_reserve_space, or (5) evbuffer_read function, which triggers a heap-based buffer overflow or an infinite loop. NOTE: this identifier was SPLIT from CVE-2014-6272 per ADT3 due to different affected versions.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade libeventUpgrade libevent-docUpgrade libevent-develUpgrade libevent-debuginfo | Apr 27, 2020 | Aug 24, 2015 |
| Debian | — | Upgrade libevent | Jul 30, 2024 | Aug 24, 2015 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libevent | Dec 4, 2019 | Aug 24, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 24, 2015 |
| Ubuntu | — | Upgrade libevent | Nov 19, 2024 | Aug 24, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub