Amazon Linux 2 : libevent (ALAS-2019-1359)

high Nessus Plugin ID 131027

Synopsis

The remote Amazon Linux 2 host is missing a security update.

Description

Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via 'insanely large inputs' to the (1) evbuffer_add, (2) evbuffer_expand, or (3) bufferevent_write function, which triggers a heap-based buffer overflow or an infinite loop. NOTE:
this identifier has been SPLIT per ADT3 due to different affected versions. See CVE-2015-6525 for the functions that are only affected in 2.0 and later. (CVE-2014-6272)

Multiple integer overflow flaws were found in the libevent's evbuffer API. An attacker able to make an application pass an excessively long input to libevent using the API could use these flaws to make the application enter an infinite loop, crash, and, possibly, execute arbitrary code. (CVE-2015-6525)

Solution

Run 'yum update libevent' to update your system.

See Also

https://alas.aws.amazon.com/AL2/ALAS-2019-1359.html

Plugin Details

Severity: High

ID: 131027

File Name: al2_ALAS-2019-1359.nasl

Version: 1.3

Type: local

Agent: unix

Published: 11/15/2019

Updated: 4/11/2024

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.5

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2015-6525

Vulnerability Information

CPE: p-cpe:/a:amazon:linux:libevent, p-cpe:/a:amazon:linux:libevent-debuginfo, p-cpe:/a:amazon:linux:libevent-devel, p-cpe:/a:amazon:linux:libevent-doc, cpe:/o:amazon:linux:2

Required KB Items: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 11/14/2019

Vulnerability Publication Date: 8/24/2015

Reference Information

CVE: CVE-2014-6272, CVE-2015-6525

ALAS: 2019-1359