CVE-2016-6263: High severity gnu libidn vulnerability
Published Sep 7, 2016
·Updated
The stringpreputf8nfkcnormalize function in lib/nfkc.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted UTF-8 data.
Affected Software
1 affected component
GNU libidn<=1.32
Remediation
Event History
Sep 7, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6263?
CVE-2016-6263 is classified as a denial of service vulnerability that can lead to application crashes.
2
How do I fix CVE-2016-6263?
To mitigate CVE-2016-6263, you should upgrade to libidn version 1.33 or later.
3
Who is affected by CVE-2016-6263?
CVE-2016-6263 affects users of libidn versions prior to 1.33.
4
What happens if I am exploited by CVE-2016-6263?
An exploit of CVE-2016-6263 can result in an application crash due to an out-of-bounds read.
5
Are there any known exploits for CVE-2016-6263?
While there are no public exploits specifically for CVE-2016-6263, the vulnerability can be triggered by sending crafted UTF-8 data.