{"id":"MGASA-2015-0009","summary":"Updated libevent packages fix CVE-2014-6272","details":"Updated libevent packages fix security vulnerability:\n\nAndrew Bartlett of Catalyst reported a defect affecting certain applications\nusing the Libevent evbuffer API. This defect leaves applications which pass\ninsanely large inputs to evbuffers open to a possible heap overflow or\ninfinite loop. In order to exploit this flaw, an attacker needs to be able to\nfind a way to provoke the program into trying to make a buffer chunk larger\nthan what will fit into a single size_t or off_t (CVE-2014-6272).\n","modified":"2026-04-16T01:48:01.673202697Z","published":"2015-01-07T15:14:58Z","upstream":["CVE-2014-6272"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2015-0009.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=14970"},{"type":"WEB","url":"https://www.debian.org/security/2015/dsa-3119"}],"affected":[{"package":{"name":"libevent","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/libevent?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.21-5.1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0009.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}