Description
Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (segmentation fault) via vectors involving a long string in brackets in the ip_as_string argument.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-824-1 | libevent security update |
Debian DSA |
DSA-3789-1 | libevent security update |
EUVD |
EUVD-2016-1381 | Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (segmentation fault) via vectors involving a long string in brackets in the ip_as_string argument. |
Ubuntu USN |
USN-3228-1 | libevent vulnerabilities |
Ubuntu USN |
USN-3278-1 | Thunderbird vulnerabilities |
References
History
Tue, 25 Nov 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | ||
| Vendors & Products |
Mozilla firefox Esr
|
Mon, 21 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:mozilla:firefox:52.0:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T03:14:42.884Z
Reserved: 2017-02-01T00:00:00.000Z
Link: CVE-2016-10196
No data.
Status : Modified
Published: 2017-03-15T15:59:00.437
Modified: 2026-05-13T00:24:29.033
Link: CVE-2016-10196
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN