CVE-2016-6261: High severity suse linux vulnerability
Published Sep 7, 2016
·Updated
The idnatoascii4i function in lib/idna.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via 64 bytes of input.
Affected Software
5 affected components
openSUSE Leap=42.1
GNU libidn<=1.32
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Remediation
Event History
Sep 7, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6261?
CVE-2016-6261 has been classified as a denial of service vulnerability.
2
How do I fix CVE-2016-6261?
To fix CVE-2016-6261, you should upgrade libidn to version 1.33 or later.
3
Which versions of libidn are affected by CVE-2016-6261?
CVE-2016-6261 affects libidn versions prior to 1.33.
4
Is CVE-2016-6261 exploitable remotely?
Yes, CVE-2016-6261 can be exploited by context-dependent attackers without needing physical access.
5
What operating systems are impacted by CVE-2016-6261?
CVE-2016-6261 affects OpenSUSE Leap 42.1 and various versions of Ubuntu Linux (12.04, 14.04, and 16.04).