--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2015-11621
2015-07-14 12:26:37
--------------------------------------------------------------------------------

Name        : libidn
Product     : Fedora 21
Version     : 1.31
Release     : 1.fc21
URL         : http://www.gnu.org/software/libidn/
Summary     : Internationalized Domain Name support library
Description :
GNU Libidn is an implementation of the Stringprep, Punycode and
IDNA specifications defined by the IETF Internationalized Domain
Names (IDN) working group, used for internationalized domain
names.

--------------------------------------------------------------------------------
Update Information:

Security fix for CVE-2015-2059
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 13 2015 Miroslav Lichvar  - 1.31-1.fc21
- update to 1.31 (CVE-2015-2059)
* Tue Mar 31 2015 gil cattaneo  1.28-6
- build java libidn library
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1197796 - CVE-2015-2059 libidn: out-of-bounds read with stringprep on invalid UTF-8
        https://bugzilla.redhat.com/show_bug.cgi?id=1197796
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use
su -c 'yum update libidn' at the command line.
For more information, refer to "Managing Software with yum",
available at .

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/

Fedora 21: libidn Security Update

July 29, 2015
Security fix for CVE-2015-2059

Summary

GNU Libidn is an implementation of the Stringprep, Punycode and

IDNA specifications defined by the IETF Internationalized Domain

Names (IDN) working group, used for internationalized domain

names.

Update Information:

Security fix for CVE-2015-2059

Change Log

* Mon Jul 13 2015 Miroslav Lichvar - 1.31-1.fc21 - update to 1.31 (CVE-2015-2059) * Tue Mar 31 2015 gil cattaneo 1.28-6 - build java libidn library

References

[ 1 ] Bug #1197796 - CVE-2015-2059 libidn: out-of-bounds read with stringprep on invalid UTF-8 https://bugzilla.redhat.com/show_bug.cgi?id=1197796

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update libidn' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
Name : libidn
Product : Fedora 21
Version : 1.31
Release : 1.fc21
URL : http://www.gnu.org/software/libidn/
Summary : Internationalized Domain Name support library

Related News