The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to read system memory and possibly have other unspecified impact via invalid UTF-8 characters in a string, which triggers an out-of-bounds read.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libidn | Sep 20, 2017 | Aug 12, 2015 |
| Debian | — | Upgrade libidn | May 14, 2016 | Aug 12, 2015 |
| Freebsd | — | Upgrade libidn | Dec 10, 2025 | Jul 23, 2015 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Aug 12, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 23, 2015 |
| Suse | — | Upgrade libidn11-32bitUpgrade libidn-develUpgrade libidn11Upgrade sles12-docker-imageUpgrade sles12sp1-docker-imageUpgrade libidn2-develUpgrade libidn-32bitUpgrade libidn-toolsUpgrade libidn2-0Upgrade libidn-x86Upgrade libidnUpgrade libidn2-0-32bitUpgrade wget | Dec 18, 2015 | Aug 12, 2015 |
| Ubuntu | — | Upgrade libidn11 | Aug 24, 2016 | Aug 12, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub