First published: Wed Sep 07 2016(Updated: )
idn in GNU libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Linux | =42.1 | |
SUSE Linux | =13.2 | |
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
GNU Libidn | <=1.32 |
http://git.savannah.gnu.org/cgit/libidn.git/commit/?id=570e68886c41c2e765e6218cb317d9a9a447a041
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8948 is classified as a medium severity vulnerability, allowing potential data leakage.
To fix CVE-2015-8948, update GNU libidn to version 1.33 or later.
CVE-2015-8948 affects systems using GNU libidn versions prior to 1.33, including certain versions of openSUSE and Ubuntu Linux.
CVE-2015-8948 may enable remote attackers to exploit an out-of-bounds read that exposes sensitive memory information.
CVE-2015-8948 is less of a concern for systems that have been updated beyond GNU libidn version 1.32.