Debian Security Advisory
DSA-3658-1 libidn -- security update
- Date Reported:
- 01 Sep 2016
- Affected Packages:
- libidn
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2015-8948, CVE-2016-6261, CVE-2016-6263.
- More information:
-
Hanno Boeck discovered multiple vulnerabilities in libidn, the GNU library for Internationalized Domain Names (IDNs), allowing a remote attacker to cause a denial of service against an application using the libidn library (application crash).
For the stable distribution (jessie), these problems have been fixed in version 1.29-1+deb8u2.
For the testing distribution (stretch), these problems have been fixed in version 1.33-1.
For the unstable distribution (sid), these problems have been fixed in version 1.33-1.
We recommend that you upgrade your libidn packages.