DSA-6493-1 libevent - security update
Checked 27 Sep 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher sourcePUBLISHER UPDATE · DSA-6493-1
DSA-6493-1 libevent - security update
Scope: Debian. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.
Several vulnerabilities were discovered in libevent, an asynchronous event notification library. The HTTP implementation (evhttp) handled Transfer-Encoding and Content-Length headers, chunked-encoding line terminators, header line folding and chunked trailers too permissively, which could allow HTTP request smuggling, header injection or access control bypass when a libevent-based server or client is combined with an HTTP proxy. Out-of-bounds memory accesses in the DNS (evdns), tagged RPC (evtag/evrpc) and buffered socket (bufferevent) code, and a use-after-free in evbuffer, could result in denial of service or potentially the execution of arbitrary code when processing untrusted input. https://security-tracker.debian.org/tracker/DSA-6493-1
Not stated. The verified publisher record does not contain a known-issues statement.
Review the official publisher document before deployment.
These links connect the publisher update to related Lifecycle records without treating the update publication date as an end-of-support date.
Checked 27 Sep 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher source