Andrew Bartlett discovered that libevent incorrectly handled large inputs to the evbuffer API. A remote attacker could possibly use this issue with an application that uses libevent to cause a denial of service, or possibly execute arbitrary code.
{ "availability": "No subscription required", "binaries": [ { "binary_version": "2.0.21-stable-1ubuntu1.14.04.1", "binary_name": "libevent-2.0-5" }, { "binary_version": "2.0.21-stable-1ubuntu1.14.04.1", "binary_name": "libevent-core-2.0-5" }, { "binary_version": "2.0.21-stable-1ubuntu1.14.04.1", "binary_name": "libevent-dbg" }, { "binary_version": "2.0.21-stable-1ubuntu1.14.04.1", "binary_name": "libevent-dev" }, { "binary_version": "2.0.21-stable-1ubuntu1.14.04.1", "binary_name": "libevent-extra-2.0-5" }, { "binary_version": "2.0.21-stable-1ubuntu1.14.04.1", "binary_name": "libevent-openssl-2.0-5" }, { "binary_version": "2.0.21-stable-1ubuntu1.14.04.1", "binary_name": "libevent-pthreads-2.0-5" } ] }