Advisories ยป MGASA-2016-0269

Updated libidn packages fix security vulnerability

Publication date: 26 Jul 2016
Modification date: 26 Jul 2016
Type: security
Affected Mageia releases : 5
CVE: CVE-2016-6261 , CVE-2015-8948 , CVE-2016-6262 , CVE-2016-6263

Description

Out-of-bounds stack read in libidn before 1.33 in idna_to_ascii_4i
(CVE-2016-6261).

Out-of-bounds-read in libidn when reading one zero byte as input
(CVE-2015-8948, CVE-2016-6262).

In libidn before 1.33, stringprep_utf8_nfkc_normalize would crash when
presented with invalid UTF-8 (CVE-2016-6263).
                

References

SRPMS

5/core