7.5
CVSSv3

CVE-2015-8948

Published: 07/09/2016 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

idn in GNU libidn prior to 1.33 might allow remote malicious users to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse leap 42.1

opensuse opensuse 13.2

canonical ubuntu linux 12.04

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

gnu libidn

Vendor Advisories

Several security issues were fixed in Libidn ...
Hanno Boeck discovered multiple vulnerabilities in libidn, the GNU library for Internationalized Domain Names (IDNs), allowing a remote attacker to cause a denial of service against an application using the libidn library (application crash) For the stable distribution (jessie), these problems have been fixed in version 129-1+deb8u2 For the test ...
idn in GNU libidn before 133 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read ...