Input validation error in Libidn2 - CVE-2019-12290

 

Input validation error in Libidn2 - CVE-2019-12290

Published: October 30, 2019


Vulnerability identifier: #VU22428
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12290
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to libidn2 fails to perform roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. A remote attacker can use a specially crafted domain name to impersonate a trusted website.


Affected software

Libidn2
Gentoo Linux
Amazon Linux AMI
Fedora
Opensuse
libidn2 (Ubuntu package)
libidn2 (Alpine package)
libidn2
mingw-libidn2

How to mitigate CVE-2019-12290

Install updates from vendor's website.

Libidn2 - update to 2.2.0
libidn2 (Ubuntu package) - addressed in versions 2.0.4-1.1ubuntu0.2, 2.0.5-1ubuntu0.3
libidn2 - addressed in versions 2.3.0-1.el6, 2.3.0-1.el7, 2.3.0-1.fc29, 2.3.0-1.fc30, 2.3.0-1.fc31
mingw-libidn2 - addressed in versions 2.3.0-1.el7, 2.3.0-1.el8, 2.3.0-1.fc29, 2.3.0-1.fc30, 2.3.0-1.fc31

External References

Related Security Bulletins