Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-2059

Опубликовано: 12 авг. 2015
Источник: debian
EPSS Низкий

Описание

The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to read system memory and possibly have other unspecified impact via invalid UTF-8 characters in a string, which triggers an out-of-bounds read.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libidnfixed1.31-1package

Примечания

  • https://www.openwall.com/lists/oss-security/2015/02/23/25

  • Patch: http://git.savannah.gnu.org/cgit/libidn.git/commit/?id=2e97c2796581c27213962c77f5a8571a598f9a2e

  • This could be attributed to a misuse of a (poorly documented) API

  • but since upstream provided a patch it makes more sense to fix

  • only libidn instead of every application using it

EPSS

Процентиль: 74%
0.00827
Низкий

Связанные уязвимости

ubuntu
больше 10 лет назад

The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to read system memory and possibly have other unspecified impact via invalid UTF-8 characters in a string, which triggers an out-of-bounds read.

redhat
почти 11 лет назад

The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to read system memory and possibly have other unspecified impact via invalid UTF-8 characters in a string, which triggers an out-of-bounds read.

nvd
больше 10 лет назад

The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to read system memory and possibly have other unspecified impact via invalid UTF-8 characters in a string, which triggers an out-of-bounds read.

github
больше 3 лет назад

The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to read system memory and possibly have other unspecified impact via invalid UTF-8 characters in a string, which triggers an out-of-bounds read.

suse-cvrf
больше 9 лет назад

Security update for wget

EPSS

Процентиль: 74%
0.00827
Низкий
Уязвимость CVE-2015-2059