GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.1.15, < 1.44CPE matchmatch criteria | cpe:2.3:a:gnu:libidn:*:*:*:*:*:*:*:* | ||
>= 0, < 1.44CPE match | cpe:2.3:a:gnu:libidn:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.