Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-2059

Опубликовано: 23 фев. 2015
Источник: redhat
CVSS2: 2.6

Описание

The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to read system memory and possibly have other unspecified impact via invalid UTF-8 characters in a string, which triggers an out-of-bounds read.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libidnWill not fix
Red Hat Enterprise Linux 6libidnWill not fix
Red Hat Enterprise Linux 7libidnWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1197796libidn: out-of-bounds read with stringprep on invalid UTF-8

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to read system memory and possibly have other unspecified impact via invalid UTF-8 characters in a string, which triggers an out-of-bounds read.

nvd
больше 10 лет назад

The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to read system memory and possibly have other unspecified impact via invalid UTF-8 characters in a string, which triggers an out-of-bounds read.

debian
больше 10 лет назад

The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in ...

github
больше 3 лет назад

The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to read system memory and possibly have other unspecified impact via invalid UTF-8 characters in a string, which triggers an out-of-bounds read.

suse-cvrf
больше 9 лет назад

Security update for wget

2.6 Low

CVSS2