The append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.3 allows remote attackers to cause a denial of service (out-of-bounds read) by clearing the high bit of the byte after invalid utf-8 encoded data.
https://security.gentoo.org/glsa/201604-04
http://www.ubuntu.com/usn/USN-2982-1
http://www.openwall.com/lists/oss-security/2016/05/10/3
http://www.openwall.com/lists/oss-security/2016/04/29/8