Security update for libidn
This update for libidn fixes the following issues: - CVE-2016-6262 and CVE-2015-8948: Out-of-bounds-read when reading one zero byte as input (bsc#990189) - CVE-2016-6261: Out-of-bounds stack read in idna_to_ascii_4i (bsc#990190) - CVE-2016-6263: stringprep_utf8_nfkc_normalize reject invalid UTF-8 (bsc#990191) - CVE-2015-2059: out-of-bounds read with stringprep on invalid UTF-8 (bsc#923241)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for libidn fixes the following issues: - CVE-2016-6262 and CVE-2015-8948: Out-of-bounds-read when reading one zero byte as input (bsc#990189) - CVE-2016-6261: Out-of-bounds stack read in idna_to_ascii_4i (bsc#990190) - CVE-2016-6263: stringprep_utf8_nfkc_normalize reject invalid UTF-8 (bsc#990191) - CVE-2015-2059: out-of-bounds read with stringprep on invalid UTF-8 (bsc#923241)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/923241
- https://bugzilla.suse.com/990189
- https://bugzilla.suse.com/990190
- https://bugzilla.suse.com/990191
- https://www.suse.com/security/cve/CVE-2015-2059
- https://www.suse.com/security/cve/CVE-2015-8948
- https://www.suse.com/security/cve/CVE-2016-6261
- https://www.suse.com/security/cve/CVE-2016-6262
- https://www.suse.com/security/cve/CVE-2016-6263
- https://www.suse.com/support/update/announcement/2016/suse-su-20162291-1/