An out-of-bounds stack read was found in idna_to_ascii_4i. Upstream patches: http://git.savannah.gnu.org/cgit/libidn.git/commit/?id=f20ce1128fb7f4d33297eee307dddaf0f92ac72d test: http://git.savannah.gnu.org/cgit/libidn.git/commit/?id=9a1a7e15d0706634971364493fbb06e77e74726c changelog: http://git.savannah.gnu.org/cgit/libidn.git/commit/?id=d4c533a5d975bf49090d3cd40acd230b8f79dd32 fix for introduced memory leak: http://git.savannah.gnu.org/cgit/libidn.git/commit/?id=11abd0e02c16f9e0b6944aea4ef0f2df44b42dd4 CVE assignment: http://seclists.org/oss-sec/2016/q3/124
Created libidn tracking bugs for this issue: Affects: fedora-all [bug 1359146]
Created mingw-libidn tracking bugs for this issue: Affects: fedora-all [bug 1359147] Affects: epel-7 [bug 1359148]
libidn-1.33-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
libidn-1.33-1.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.