Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-2059

Опубликовано: 12 авг. 2015
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to read system memory and possibly have other unspecified impact via invalid UTF-8 characters in a string, which triggers an out-of-bounds read.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gnu:libidn:*:*:*:*:*:*:*:*
Версия до 1.30 (включая)
Конфигурация 2

Одно из

cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*

EPSS

Процентиль: 74%
0.00827
Низкий

7.5 High

CVSS2

Дефекты

CWE-119

Связанные уязвимости

ubuntu
больше 10 лет назад

The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to read system memory and possibly have other unspecified impact via invalid UTF-8 characters in a string, which triggers an out-of-bounds read.

redhat
почти 11 лет назад

The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to read system memory and possibly have other unspecified impact via invalid UTF-8 characters in a string, which triggers an out-of-bounds read.

debian
больше 10 лет назад

The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in ...

github
больше 3 лет назад

The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to read system memory and possibly have other unspecified impact via invalid UTF-8 characters in a string, which triggers an out-of-bounds read.

suse-cvrf
больше 9 лет назад

Security update for wget

EPSS

Процентиль: 74%
0.00827
Низкий

7.5 High

CVSS2

Дефекты

CWE-119