CVE-2015-8948: High severity suse linux vulnerability
Published Sep 7, 2016
·Updated
idn in GNU libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read.
Affected Software
6 affected components
openSUSE Leap=42.1
openSUSE openSUSE=13.2
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
GNU libidn<=1.32
Remediation
Event History
Sep 7, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8948?
CVE-2015-8948 is classified as a medium severity vulnerability, allowing potential data leakage.
2
How do I fix CVE-2015-8948?
To fix CVE-2015-8948, update GNU libidn to version 1.33 or later.
3
Who is affected by CVE-2015-8948?
CVE-2015-8948 affects systems using GNU libidn versions prior to 1.33, including certain versions of openSUSE and Ubuntu Linux.
4
What type of attack is possible with CVE-2015-8948?
CVE-2015-8948 may enable remote attackers to exploit an out-of-bounds read that exposes sensitive memory information.
5
Is CVE-2015-8948 still a concern for current systems?
CVE-2015-8948 is less of a concern for systems that have been updated beyond GNU libidn version 1.32.