vulnerability
FreeBSD: libidn -- mulitiple vulnerabilities (Multiple CVEs)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 4 | (AV:N/AC:L/Au:N/C:N/I:N/A:P) | Jul 20, 2016 | Aug 2, 2016 | Feb 18, 2025 |
Severity
4
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Jul 20, 2016
Added
Aug 2, 2016
Modified
Feb 18, 2025
Description
Simon Josefsson reports:
libidn: Fix out-of-bounds stack read in idna_to_ascii_4i.
idn: Solve out-of-bounds-read when reading one zero byte as input.
Also replaced fgets with getline.
libidn: stringprep_utf8_nfkc_normalize reject invalid UTF-8. It was
always documented to only accept UTF-8 data, but now it doesn't
crash when presented with such data.
Solution
freebsd-upgrade-package-libidn
References
- CVE-2015-8948
- https://attackerkb.com/topics/CVE-2015-8948
- CVE-2016-6261
- https://attackerkb.com/topics/CVE-2016-6261
- CVE-2016-6262
- https://attackerkb.com/topics/CVE-2016-6262
- CVE-2016-6263
- https://attackerkb.com/topics/CVE-2016-6263
- URL-http://www.openwall.com/lists/oss-security/2016/07/21/4
- URL-https://lists.gnu.org/archive/html/help-libidn/2016-07/msg00009.html
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.