Lucene search

K
debianDebianDEBIAN:DLA-137-1:3BA40
HistoryJan 26, 2015 - 10:50 a.m.

[SECURITY] [DLA 137-1] libevent security update

2015-01-2610:50:10
lists.debian.org
11

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

9.6

Confidence

High

EPSS

0.005

Percentile

75.3%

Package : libevent
Version : 1.4.13-stable-1+deb6u1
CVE ID : CVE-2014-6272
Debian Bug : 774645

The libevent library was vulnerable to a potential heap overflow in
the buffer/bufferevent APIs.

This update was prepared by Nguyen Cong who used the upstream-provided
patch. Thanks to them!

RaphaΓ«l Hertzog β—ˆ Debian Developer

Support Debian LTS: http://www.freexian.com/services/debian-lts.html
Learn to master Debian: http://debian-handbook.info/get/
Attachment:
signature.asc
Description: Digital signature

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

9.6

Confidence

High

EPSS

0.005

Percentile

75.3%