Описание
GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.
Ссылки
- ExploitMailing List
- Mailing List
Уязвимые конфигурации
Конфигурация 1Версия от 0.1.15 (включая) до 1.44 (исключая)
cpe:2.3:a:gnu:libidn:*:*:*:*:*:*:*:*
EPSS
Процентиль: 4%
0.00147
Низкий
4 Medium
CVSS3
2.5 Low
CVSS3
Дефекты
CWE-1284
CWE-1284
Связанные уязвимости
CVSS3: 4
ubuntu
около 1 месяца назад
GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.
CVSS3: 4
debian
около 1 месяца назад
GNU libidn before 1.44 is prone to out-of-bounds reads ofuninitialized ...
CVSS3: 4
github
около 1 месяца назад
GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.
EPSS
Процентиль: 4%
0.00147
Низкий
4 Medium
CVSS3
2.5 Low
CVSS3
Дефекты
CWE-1284
CWE-1284