vulnerability

FreeBSD: libidn -- mulitiple vulnerabilities (Multiple CVEs)

Severity
4
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Jul 20, 2016
Added
Aug 2, 2016
Modified
Feb 18, 2025

Description



Simon Josefsson reports:

libidn: Fix out-of-bounds stack read in idna_to_ascii_4i.
idn: Solve out-of-bounds-read when reading one zero byte as input.
Also replaced fgets with getline.
libidn: stringprep_utf8_nfkc_normalize reject invalid UTF-8. It was
always documented to only accept UTF-8 data, but now it doesn't
crash when presented with such data.

Solution

freebsd-upgrade-package-libidn
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.