Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Ubuntu 12.04 ESM: USN-3434-2 Critical: Libidn Denial of Service

Ubuntu Large Esm H500
Libidn could be made to crash or run programs if it processed specially crafted input.
=========================================================================Ubuntu Security Notice USN-3434-2
October 23, 2017

libidn vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 ESM

Summary:

Libidn could be made to crash or run programs if it processed specially
crafted input.

Software Description:
- libidn: implementation of IETF IDN specifications

Details:

USN-3434-1 fixed a vulnerability in  Libidn. This update
provides the corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

 It was discovered that Libidn incorrectly handled decoding certain
 digits. A remote attacker could use this issue to cause Libidn to
 crash, resulting in a denial of service, or possibly execute arbitrary
 code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  libidn11                        1.23-2ubuntu0.2

In general, a standard system update will make all the necessary
changes.

References:
  https://ubuntu.com/security/notices/USN-3434-2
  https://ubuntu.com/security/notices/USN-3434-1
  CVE-2017-14062

Ubuntu 12.04 ESM: USN-3434-2 Critical: Libidn Denial of Service

ubuntu
Calendar Grey October 23, 2017
Dist Ubuntu Esm H88
Address Libidn security flaw in Ubuntu 12.04 ESM to mitigate potential crash threats and strengthen system integrity.
Libidn could be made to crash or run programs if it processed specially crafted input.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM:   libidn11                        1.23-2ubuntu0.2 In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-3434-2

  https://ubuntu.com/security/notices/USN-3434-1

  CVE-2017-14062

Severity
critical
Lowest
Low
Medium
High
Critical

October 23, 2017

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here