First published: Wed Sep 07 2016(Updated: )
The stringprep_utf8_nfkc_normalize function in lib/nfkc.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted UTF-8 data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU libidn | <=1.32 |
http://git.savannah.gnu.org/cgit/libidn.git/commit/?id=1fbee57ef3c72db2206dd87e4162108b2f425555
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.