Integer overflow in the decode_digit function in puny_decode.c in Libidn2 before 2.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libidnUpgrade libidn2-0 | Oct 2, 2017 | Aug 31, 2017 |
| Gentoo Linux | — | Upgrade sys-libs/glibc. | Apr 5, 2018 | Aug 31, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libidn | Nov 3, 2020 | Aug 31, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libidn | Jan 20, 2021 | Aug 31, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libidn | Nov 2, 2020 | Aug 31, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 30, 2017 |
| Suse | — | Upgrade libidn11-32bitUpgrade libidn-32bitUpgrade libidn-x86Upgrade libidn-toolsUpgrade libidn-develUpgrade libidnUpgrade libidn11 | Apr 6, 2018 | Aug 31, 2017 |
| Ubuntu | — | Upgrade libidn2-0Upgrade libidn2-0 (Ubuntu Pro)Upgrade idn2 (Ubuntu Pro)Upgrade idn2Upgrade libidn11 | Sep 19, 2017 | Aug 31, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub