7.5
CVSSv2

CVE-2015-2059

Published: 12/08/2015 Updated: 30/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The stringprep_utf8_to_ucs4 function in libin prior to 1.31, as used in jabberd2, allows context-dependent malicious users to read system memory and possibly have other unspecified impact via invalid UTF-8 characters in a string, which triggers an out-of-bounds read.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu libidn

opensuse opensuse 13.2

opensuse opensuse 13.1

fedoraproject fedora 21

fedoraproject fedora 22

Vendor Advisories

Several security issues were fixed in Libidn ...