Search CVE reports
1 – 4 of 4 results
Some fixes available 2 of 4
idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string.
2 affected packages
libidn2, libidn2-0
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libidn2 | Not affected | Not affected | Not affected | Fixed |
libidn2-0 | Not in release | Not in release | Not in release | Not in release |
Some fixes available 2 of 4
GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By creating...
2 affected packages
libidn2, libidn2-0
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libidn2 | Not affected | Not affected | Not affected | Fixed |
libidn2-0 | Not in release | Not in release | Not in release | Not in release |
Integer overflow in the decode_digit function in puny_decode.c in Libidn2 before 2.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact.
3 affected packages
libidn, libidn2, libidn2-0
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libidn | — | Not affected | Not affected | Not affected |
libidn2 | — | Not affected | Not affected | Not affected |
libidn2-0 | — | Not in release | Not in release | Not in release |
Integer overflow in the _isBidi function in bidi.c in Libidn2 before 2.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact.
2 affected packages
libidn, libidn2-0
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libidn | — | — | — | — |
libidn2-0 | — | — | — | — |