CVE编号
CVE-2016-10195利用情况
暂无补丁情况
官方补丁披露时间
2017-03-16漏洞描述
2.1.6-beta之前的libevent中的evdns.c中的name_parse函数使远程攻击者可以通过涉及label_len变量的向量来产生未指定的影响,其触发越界堆栈读取。解决建议
用户可联系供应商获得补丁信息:http://libevent.org/
参考链接 |
|
---|---|
http://www.debian.org/security/2017/dsa-3789 | |
http://www.openwall.com/lists/oss-security/2017/01/31/17 | |
http://www.openwall.com/lists/oss-security/2017/02/02/7 | |
http://www.securityfocus.com/bid/96014 | |
http://www.securitytracker.com/id/1038320 | |
https://access.redhat.com/errata/RHSA-2017:1104 | |
https://access.redhat.com/errata/RHSA-2017:1106 | |
https://access.redhat.com/errata/RHSA-2017:1201 | |
https://github.com/libevent/libevent/blob/release-2.1.6-beta/ChangeLog | |
https://github.com/libevent/libevent/commit/96f64a022014a208105ead6c8a7066018449d86d | |
https://github.com/libevent/libevent/issues/317 | |
https://security.gentoo.org/glsa/201705-01 |
受影响软件情况
# | 类型 | 厂商 | 产品 | 版本 | 影响面 | ||||
1 | |||||||||
---|---|---|---|---|---|---|---|---|---|
运行在以下环境 | |||||||||
应用 | libevent_project | libevent | * |
Up to (including) 2.1.5 |
|||||
运行在以下环境 | |||||||||
系统 | debian | DPKG | * |
Up to (excluding) 2.0.21-stable-3 |
|||||
运行在以下环境 | |||||||||
系统 | redhat_6 | firefox | * |
Up to (excluding) 0:52.1.0-2.el6_9 |
|||||
运行在以下环境 | |||||||||
系统 | redhat_7 | firefox | * |
Up to (excluding) 0:52.1.0-2.el7_3 |
|||||
运行在以下环境 | |||||||||
系统 | redhat_7 | thunderbird | * |
Up to (excluding) 0:52.1.0-1.el7_3 |
|||||
运行在以下环境 | |||||||||
系统 | suse_12 | libevent-2_0-5 | * |
Up to (excluding) 2.0.21-6.3 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_12.04_lts | libevent | * |
Up to (excluding) 2.0.16-stable-1ubuntu0.2 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_14.04_lts | firefox | * |
Up to (excluding) 53.0+build6-0ubuntu0.14.04.1 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_14.04_lts | libevent | * |
Up to (excluding) 2.0.21-stable-1ubuntu1.14.04.2 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_16.04_lts | firefox | * |
Up to (excluding) 53.0+build6-0ubuntu0.16.04.1 |
|||||
- 攻击路径 远程
- 攻击复杂度 复杂
- 权限要求 无需权限
- 影响范围 有限影响
- EXP成熟度 未验证
- 补丁情况 官方补丁
- 数据保密性 无影响
- 数据完整性 无影响
- 服务器危害 无影响
- 全网数量 100
还没有评论,来说两句吧...