aboutsummaryrefslogtreecommitdiffstats
path: root/english/lts/security/2015/dla-277.wml
blob: 8119b99d8b7ace10204ddc9fdfc9846504722c2b (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
<define-tag description>LTS security update</define-tag>
<define-tag moreinfo>
<p>Thijs Alkemade discovered that the Jabber server may pass an invalid
UTF-8 string to libidn, the GNU library for Internationalized Domain
Names (IDNs).  In the case of the Jabber server, this results in
information disclosure, and it is likely that some other applications
using libidn have similar vulnerabilities.  This update changes libidn
to check for invalid strings rather than assuming that the application
has done so.</p>

<p>For the oldoldstable distribution (squeeze), this problem has been
fixed in version 1.15-2+deb6u1.</p>

<p>For the oldstable distribution (wheezy) and stable distribution
(jessie), this problem will be fixed soon.</p>
</define-tag>

# do not modify the following line
#include "$(ENGLISHDIR)/lts/security/2015/dla-277.data"
# $Id$

© 2014-2024 Faster IT GmbH | imprint | privacy policy