PublicDateAtUSN: 2016-07-21 Candidate: CVE-2016-6263 PublicDate: 2016-09-07 20:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6263 https://lists.gnu.org/archive/html/help-libidn/2016-07/msg00009.html http://www.openwall.com/lists/oss-security/2016/07/20/6 https://ubuntu.com/security/notices/USN-3068-1 Description: The stringprep_utf8_nfkc_normalize function in lib/nfkc.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted UTF-8 data. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Hanno Böck Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_libidn: upstream: http://git.savannah.gnu.org/cgit/libidn.git/commit/?id=1fbee57ef3c72db2206dd87e4162108b2f425555 upstream_libidn: released (1.33-1) precise_libidn: released (1.23-2ubuntu0.1) precise/esm_libidn: released (1.23-2ubuntu0.1) trusty_libidn: released (1.28-1ubuntu2.1) trusty/esm_libidn: released (1.28-1ubuntu2.1) vivid/stable-phone-overlay_libidn: ignored (reached end-of-life) vivid/ubuntu-core_libidn: released (1.28-1ubuntu2.15.04.1) wily_libidn: ignored (reached end-of-life) xenial_libidn: released (1.32-3ubuntu1.1) esm-infra/xenial_libidn: released (1.32-3ubuntu1.1) yakkety_libidn: not-affected (1.33-1) zesty_libidn: not-affected (1.33-1) devel_libidn: not-affected (1.33-1)