CVE-2015-2059
Publication date 12 August 2015
Last updated 24 July 2024
Ubuntu priority
The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to read system memory and possibly have other unspecified impact via invalid UTF-8 characters in a string, which triggers an out-of-bounds read.
Status
Package | Ubuntu Release | Status |
---|---|---|
libidn | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Fixed 1.28-1ubuntu2.1
|
|
Notes
References
Related Ubuntu Security Notices (USN)
- USN-3068-1
- Libidn vulnerabilities
- 24 August 2016