7.5
CVSSv3

CVE-2016-6263

Published: 07/09/2016 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The stringprep_utf8_nfkc_normalize function in lib/nfkc.c in libidn prior to 1.33 allows context-dependent malicious users to cause a denial of service (out-of-bounds read and crash) via crafted UTF-8 data.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu libidn

Vendor Advisories

Several security issues were fixed in Libidn ...
Hanno Boeck discovered multiple vulnerabilities in libidn, the GNU library for Internationalized Domain Names (IDNs), allowing a remote attacker to cause a denial of service against an application using the libidn library (application crash) For the stable distribution (jessie), these problems have been fixed in version 129-1+deb8u2 For the test ...
The stringprep_utf8_nfkc_normalize function in lib/nfkcc in libidn before 133 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted UTF-8 data ...