Input validation error in Libidn2 - CVE-2019-12290
Published: October 30, 2019
Vulnerability identifier: #VU22428
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12290
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to libidn2 fails to perform roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. A remote attacker can use a specially crafted domain name to impersonate a trusted website.
Affected software
Libidn2
Gentoo Linux
Amazon Linux AMI
Fedora
Opensuse
libidn2 (Ubuntu package)
libidn2 (Alpine package)
libidn2
mingw-libidn2
Gentoo Linux
Amazon Linux AMI
Fedora
Opensuse
libidn2 (Ubuntu package)
libidn2 (Alpine package)
libidn2
mingw-libidn2
How to mitigate CVE-2019-12290
Install updates from vendor's website.
Libidn2 - update to 2.2.0
libidn2 (Ubuntu package) - addressed in versions 2.0.4-1.1ubuntu0.2, 2.0.5-1ubuntu0.3
libidn2 - addressed in versions 2.3.0-1.el6, 2.3.0-1.el7, 2.3.0-1.fc29, 2.3.0-1.fc30, 2.3.0-1.fc31
mingw-libidn2 - addressed in versions 2.3.0-1.el7, 2.3.0-1.el8, 2.3.0-1.fc29, 2.3.0-1.fc30, 2.3.0-1.fc31
libidn2 (Ubuntu package) - addressed in versions 2.0.4-1.1ubuntu0.2, 2.0.5-1ubuntu0.3
libidn2 - addressed in versions 2.3.0-1.el6, 2.3.0-1.el7, 2.3.0-1.fc29, 2.3.0-1.fc30, 2.3.0-1.fc31
mingw-libidn2 - addressed in versions 2.3.0-1.el7, 2.3.0-1.el8, 2.3.0-1.fc29, 2.3.0-1.fc30, 2.3.0-1.fc31
External References
Related Security Bulletins
- Spoofing attack in GNU libidn2
- Ubuntu update for Libidn2
- OpenSUSE Linux update for libidn2
- OpenSUSE Linux update for libidn2
- Amazon Linux AMI update for libidn2
- Gentoo update for GNU IDN Library 2
- Input validation error in libidn2 (Alpine package)
- Fedora 31 update for libidn2
- Fedora 30 update for libidn2
- Fedora 29 update for libidn2
- Fedora EPEL 7 update for libidn2
- Fedora EPEL 6 update for libidn2
- Fedora 31 update for mingw-libidn2
- Fedora 30 update for mingw-libidn2
- Fedora 29 update for mingw-libidn2
- Fedora EPEL 8 update for mingw-libidn2
- Fedora EPEL 7 update for mingw-libidn2