SB2016080535 - Out-of-bounds read in libidn (Alpine package)
Published: August 5, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2016-6261)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The idna_to_ascii_4i function in lib/idna.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via 64 bytes of input.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=6f8194876e62f69016a55f327bebc773747eb8cc
- https://git.alpinelinux.org/aports/commit/?id=33d33f1d2d9ecca84f682b2a549435c8b7ed96ea
- https://git.alpinelinux.org/aports/commit/?id=8a25e031b07b773c4abdabe2f55faf44b187ea5a
- https://git.alpinelinux.org/aports/commit/?id=812e0313b9eac3e50cd03f0dd965957bbe23fcf1
- https://git.alpinelinux.org/aports/commit/?id=87698baa9ec19d0554e5233954b6f266efe8b5cd
- https://git.alpinelinux.org/aports/commit/?id=bb2a0351e208d64f3b150cd56e320b0f2e74605a
- https://git.alpinelinux.org/aports/commit/?id=ffe337c3cad45e1b559788b0f80573a30530d4c1