An integer overflow vulnerability was discovered in libidn, the GNU library for Internationalized Domain Names (IDNs), in its Punycode handling (a Unicode characters to ASCII encoding) allowing a remote attacker to cause a denial of . Package : libidn Version : 1.29-1+deb8u3 CVE ID : CVE-2017-14062 Debian Bug : 873903 An integer overflow vulnerability was discovered in libidn, the GNU library for Internationalized Domain Names (IDNs), in its Punycode handling (a Unicode characters to ASCII encoding) allowing a remote attacker to cause a denial of service against applications using the library. For Debian 8 "Jessie", this problem has been fixed in version 1.29-1+deb8u3. We recommend that you upgrade your libidn packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A critical integer vulnerability has been identified in libidn impacting Debian 8 systems. Immediate upgrade is recommended to mitigate potential denial of service threats.. libidn update, integer overflow vulnerability, debian security advisory. . LinuxSecurity.com Team
Update to the latest upstream release, which fixes CVE-2017-14062.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-02e23192f5 2018-04-06 15:00:04.588443 --------------------------------------------------------------------------------Name : libidn Product : Fedora 27 Version : 1.34 Release : 1.fc27 URL : http://www.gnu.org/software/libidn/ Summary : Internationalized Domain Name support library Description : GNU Libidn is an implementation of the Stringprep, Punycode and IDNA specifications defined by the IETF Internationalized Domain Names (IDN) working group, used for internationalized domain names. --------------------------------------------------------------------------------Update Information: Update to the latest upstream release, which fixes CVE-2017-14062. --------------------------------------------------------------------------------References: [ 1 ] Bug #1486882 - CVE-2017-14062 libidn2: Integer overflow in puny_decode.c/decode_digit https://bugzilla.redhat.com/show_bug.cgi?id=1486882 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libidn' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Update to the latest upstream release, which fixes CVE-2017-14062.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-02e23192f5 2018-04-06 15:00:04.588443 --------------------------------------------------------------------------------Name : libidn Product : Fedora 27 Version : 1.34 Release : 1.fc27 URL : Summary : Internationalized Domain Name support library Description : GNU Libidn is an implementation of the Stringprep, Punycode and IDNA specifications defined by the IETF Internationalized Domain Names (IDN) working group, used for internationalized domain names. --------------------------------------------------------------------------------Update Information: Update to the latest upstream release, which fixes CVE-2017-14062. --------------------------------------------------------------------------------References: [ 1 ] Bug #1486882 - CVE-2017-14062 libidn2: Integer overflow in puny_decode.c/decode_digit https://bugzilla.redhat.com/show_bug.cgi?id=1486882 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libidn' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Update to the latest upstream release, which fixes CVE-2017-14062.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-f749c70191 2018-04-06 11:07:50.699727 --------------------------------------------------------------------------------Name : libidn Product : Fedora 28 Version : 1.34 Release : 1.fc28 URL : http://www.gnu.org/software/libidn/ Summary : Internationalized Domain Name support library Description : GNU Libidn is an implementation of the Stringprep, Punycode and IDNA specifications defined by the IETF Internationalized Domain Names (IDN) working group, used for internationalized domain names. --------------------------------------------------------------------------------Update Information: Update to the latest upstream release, which fixes CVE-2017-14062. --------------------------------------------------------------------------------References: [ 1 ] Bug #1486882 - CVE-2017-14062 libidn2: Integer overflow in puny_decode.c/decode_digit https://bugzilla.redhat.com/show_bug.cgi?id=1486882 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libidn' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Update to the latest upstream release, which fixes CVE-2017-14062.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-f749c70191 2018-04-06 11:07:50.699727 --------------------------------------------------------------------------------Name : libidn Product : Fedora 28 Version : 1.34 Release : 1.fc28 URL : http://www.gnu.org/software/libidn/ Summary : Internationalized Domain Name support library Description : GNU Libidn is an implementation of the Stringprep, Punycode and IDNA specifications defined by the IETF Internationalized Domain Names (IDN) working group, used for internationalized domain names. --------------------------------------------------------------------------------Update Information: Update to the latest upstream release, which fixes CVE-2017-14062. --------------------------------------------------------------------------------References: [ 1 ] Bug #1486882 - CVE-2017-14062 libidn2: Integer overflow in puny_decode.c/decode_digit https://bugzilla.redhat.com/show_bug.cgi?id=1486882 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libidn' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Libidn could be made to crash or run programs if it processed specially crafted input.. =========================================================================Ubuntu Security Notice USN-3434-2 October 23, 2017 libidn vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 ESM Summary: Libidn could be made to crash or run programs if it processed specially crafted input. Software Description: - libidn: implementation of IETF IDN specifications Details: USN-3434-1 fixed a vulnerability in Libidn. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that Libidn incorrectly handled decoding certain digits. A remote attacker could use this issue to cause Libidn to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM: libidn11 1.23-2ubuntu0.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3434-2 https://ubuntu.com/security/notices/USN-3434-1 CVE-2017-14062 . Address Libidn security flaw in Ubuntu 12.04 ESM to mitigate potential crash threats and strengthen system integrity.. Libidn Security, Ubuntu Update, Crash Risk, Denial of Service. . Severity: Critical. LinuxSecurity.com Team
It was discovered that there was an integer overflow vulnerability in libidn's Punycode handling (an encoding used to convert Unicode characters to ASCII) which would have allowed remote attackers to cause a denial of service. . Hash: SHA256 Package : libidn Version : 1.25-2+deb7u3 CVE ID : CVE-2017-14062 Debian Bug : #873903 It was discovered that there was an integer overflow vulnerability in libidn's Punycode handling (an encoding used to convert Unicode charactersto ASCII) which would have allowed remote attackers to cause a denial of service. For Debian 7 "Wheezy", this issue has been fixed in libidn version 1.25-2+deb7u3. We recommend that you upgrade your libidn packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'`
Hanno Boeck discovered multiple vulnerabilities in libidn, the GNU library for Internationalized Domain Names (IDNs), allowing a remote attacker to cause a denial of service against an application using the libidn library (application crash). . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3658-1
Get the latest Linux and open source security news straight to your inbox.