cbcvebase.
CVE-2017-14062
published 2017-08-31

CVE-2017-14062: Integer overflow in the decode_digit function in puny_decode.c in Libidn2 before 2.0.4 allows remote attackers to cause a denial of service or possibly have…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Integer overflow in the decode_digit function in puny_decode.c in Libidn2 before 2.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianlibidn< libidn 1.33-2 (bookworm)libidn 1.33-2 (bookworm)
gnulibidn>= 0 < 1.33-21.33-2
gnulibidn>= 0 < 1.33-21.33-2
gnulibidn>= 0 < 1.33-21.33-2
gnulibidn>= 0 < 1.33-21.33-2
gnulibidn2< 2.0.42.0.4

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL