PT-2015-5574 · Jabberd2+4 · Jabberd2+4

Xnyhps

·

Published

2015-08-12

·

Updated

2018-10-30

·

CVE-2015-2059

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libin versions prior to 1.31 jabberd2 (affected versions not specified)
Description The issue allows context-dependent attackers to read system memory and possibly have other unspecified impact via invalid UTF-8 characters in a string, which triggers an out-of-bounds read. This occurs due to a vulnerability in the stringprep utf8 to ucs4 function.
Recommendations For libin versions prior to 1.31, update to version 1.31 or later to resolve the issue. For jabberd2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-2098
CVE-2015-2059
DLA-277-1
DLA-476-1
DSA-3578-1
MGASA-2015-0349
OPENSUSE-SU-2024:10566-1
SUSE-SU-2016:2079-1
SUSE-SU-2016:2226-1
SUSE-SU-2016:2291-1
SUSE-SU-2016_2079-1
SUSE-SU-2016_2291-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
USN-3068-1

Affected Products

Alt Linux
Suse
Ubuntu
Jabberd2
Libin