| Summary: | <net-dns/libidn2-2.0.4: integer overflow in puny_decode.c/decode_digit | ||
|---|---|---|---|
| Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
| Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
| Status: | RESOLVED DUPLICATE | ||
| Severity: | normal | CC: | jer |
| Priority: | Normal | ||
| Version: | unspecified | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | https://bugzilla.redhat.com/show_bug.cgi?id=1486882 | ||
| See Also: | https://bugs.gentoo.org/show_bug.cgi?id=629466 | ||
| Whiteboard: | |||
| Package list: | Runtime testing required: | --- | |
*** This bug has been marked as a duplicate of bug 629466 *** |
From ${URL} : A integer overflow was found in libidn2 that could potentialy cause denial of service. Upstream patch: http://git.savannah.gnu.org/cgit/libidn/libidn2.git/commit/?h=libidn2-2.0.4&id=3284eb342cd0ed1a18786e3fcdf0cdd7e76676bd References: https://bugzilla.novell.com/show_bug.cgi?id=1056450 https://lists.gnu.org/archive/html/info-gnu/2017-08/msg00013.html @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.