ALT-PU-2019-1902-1
Closed vulnerabilities
Published: 2019-11-22
BDU:2020-01339
Уязвимость компонента RFC3490 библиотеки Libidn2, позволяющая нарушителю создать вредоносный домен, который соответствует целевому домену
Severity: HIGH (7.5)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
References:
Published: 2019-10-22
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2019-12290
GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By creating a malicious domain that matches a target domain except for the inclusion of certain punycoded Unicode characters (that would be discarded when converted first to a Unicode label and then back to an ASCII label), arbitrary domains can be impersonated.
Severity: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
References:
- openSUSE-SU-2019:2613
- openSUSE-SU-2019:2613
- openSUSE-SU-2019:2611
- openSUSE-SU-2019:2611
- https://gitlab.com/libidn/libidn2/commit/241e8f486134793cb0f4a5b0e5817a97883401f5
- https://gitlab.com/libidn/libidn2/commit/241e8f486134793cb0f4a5b0e5817a97883401f5
- https://gitlab.com/libidn/libidn2/commit/614117ef6e4c60e1950d742e3edf0a0ef8d389de
- https://gitlab.com/libidn/libidn2/commit/614117ef6e4c60e1950d742e3edf0a0ef8d389de
- https://gitlab.com/libidn/libidn2/merge_requests/71
- https://gitlab.com/libidn/libidn2/merge_requests/71
- FEDORA-2019-20e9736c97
- FEDORA-2019-20e9736c97
- FEDORA-2019-28d3cd20c0
- FEDORA-2019-28d3cd20c0
- FEDORA-2019-160303ebeb
- FEDORA-2019-160303ebeb
- FEDORA-2019-1ebb5c928e
- FEDORA-2019-1ebb5c928e
- FEDORA-2019-f454c7a118
- FEDORA-2019-f454c7a118
- GLSA-202003-63
- GLSA-202003-63
- USN-4168-1
- USN-4168-1