[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 277-1] libidn security update

Package        : libidn
Version        : 1.15-2+deb6u1
CVE ID         : CVE-2015-2059

Thijs Alkemade discovered that the Jabber server may pass an invalid
UTF-8 string to libidn, the GNU library for Internationalized Domain
Names (IDNs).  In the case of the Jabber server, this results in
information disclosure, and it is likely that some other applications
using libidn have similar vulnerabilities.  This update changes libidn
to check for invalid strings rather than assuming that the application
has done so.

For the oldoldstable distribution (squeeze), this problem has been
fixed in version 1.15-2+deb6u1.

For the oldstable distribution (wheezy) and stable distribution
(jessie), this problem will be fixed soon.

Ben Hutchings - Debian developer, member of Linux kernel and LTS teams

Attachment: signature.asc
Description: This is a digitally signed message part

Reply to: