Integer overflow in Libidn2 - CVE-2017-14062

 

Integer overflow in Libidn2 - CVE-2017-14062

Published: October 1, 2017 / Updated: October 2, 2017


Vulnerability identifier: #VU8647
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-14062
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the decode_digit function in puny_decode.c in Libidn2 before 2.0.4. A remote attacker can cause a denial of service or possibly have unspecified other impact.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Libidn2
Gentoo Linux
Debian Linux
Fedora
Ubuntu
System x Integrated Management Module (IMM2)
Flex System Integrated Management Module (IMM2)
Flex System Chassis Management Module (CMM)
Integrated Management Module II (IMM2) for BladeCenter Systems
libidn
libidn2
mingw-libidn2

How to mitigate CVE-2017-14062


System x Integrated Management Module (IMM2) - update to 1AOO84C-6.80
Flex System Integrated Management Module (IMM2) - update to 1AOO84C-6.80
Integrated Management Module II (IMM2) for BladeCenter Systems - update to 1AOO84C-6.80-bc
libidn - addressed in versions 1.34-1.fc27, 1.34-1.fc28
Flex System Chassis Management Module (CMM) - update to 2pet16c-2.5.12c
libidn2 - addressed in versions 2.0.4-1.el6, 2.0.4-1.el7, 2.0.4-1.fc25, 2.0.4-1.fc26, 2.0.4-1.fc27
mingw-libidn2 - addressed in versions 2.0.4-1.el7, 2.0.4-1.fc26, 2.0.4-1.fc27

External References

Related Security Bulletins