PT-2015-5574 · Jabberd2+4 · Jabberd2+4

Xnyhps

·

Publicado

2015-08-12

·

Atualizado

2018-10-30

·

CVE-2015-2059

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libin versions prior to 1.31 jabberd2 (affected versions not specified)
Description The issue allows context-dependent attackers to read system memory and possibly have other unspecified impact via invalid UTF-8 characters in a string, which triggers an out-of-bounds read. This occurs due to a vulnerability in the stringprep utf8 to ucs4 function.
Recommendations For libin versions prior to 1.31, update to version 1.31 or later to resolve the issue. For jabberd2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-2098
CVE-2015-2059
DLA-277-1
DLA-476-1
DSA-3578-1
MGASA-2015-0349
OPENSUSE-SU-2024:10566-1
SUSE-SU-2016:2079-1
SUSE-SU-2016:2226-1
SUSE-SU-2016:2291-1
SUSE-SU-2016_2079-1
SUSE-SU-2016_2291-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
USN-3068-1

Produtos afetados

Alt Linux
Suse
Ubuntu
Jabberd2
Libin