CVE-2016-6262: High severity gnu libidn vulnerability
Published Sep 7, 2016
·Updated
idn in libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read, a different vulnerability than CVE-2015-8948.
Affected Software
6 affected components
GNU libidn<=1.32
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
openSUSE Leap=42.1
openSUSE openSUSE=13.2
Remediation
Event History
Sep 7, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6262?
CVE-2016-6262 is considered a medium severity vulnerability due to the potential for sensitive memory information disclosure.
2
How do I fix CVE-2016-6262?
To fix CVE-2016-6262, upgrade libidn to version 1.33 or later.
3
What types of systems are affected by CVE-2016-6262?
CVE-2016-6262 affects GNU libidn versions prior to 1.33 and various versions of Ubuntu and openSUSE.
4
What can an attacker achieve with CVE-2016-6262?
An attacker exploiting CVE-2016-6262 might obtain sensitive memory data from the affected system.
5
Is CVE-2016-6262 related to any other vulnerabilities?
CVE-2016-6262 is a different vulnerability than CVE-2015-8948, though both involve issues in the same library.