CVE-2015-2059: Buffer Overflow
The stringpreputf8toucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to read system memory and possibly have other unspecified impact via invalid UTF-8 characters in a string, which triggers an out-of-bounds read.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2059?
CVE-2015-2059 has a severity rating that indicates it allows attackers to exploit memory vulnerabilities through invalid UTF-8 characters.
How do I fix CVE-2015-2059?
To fix CVE-2015-2059, update libidn to version 1.31 or later.
What software is affected by CVE-2015-2059?
CVE-2015-2059 affects GNU libidn versions up to 1.30, as well as specific versions of openSUSE and Fedora.
Can CVE-2015-2059 lead to data loss?
CVE-2015-2059 may allow context-dependent attackers to read system memory, potentially leading to sensitive data exposure.
What are the potential impacts of CVE-2015-2059?
The potential impacts of CVE-2015-2059 include unauthorized memory access and possible disruption of application behavior.