Several vulnerabilities were discovered in libevent, an asynchronous event notification library. The HTTP implementation (evhttp) handled Transfer-Encoding and Content-Length headers, chunked-encoding line terminators, header line folding and chunked trailers too permissively, which could allow HTTP request smuggling, header injection or access... Weiterlesen: DSA-6493-1 libevent - security update
Intelligence View
⚡ tsecurity.de Intelligence
DSA-6493-1 libevent - security update
Several vulnerabilities were discovered in libevent, an asynchronous event notification library. The HTTP implementation (evhttp) handled Transfer-Encoding and…