Bugzilla – Bug 1154884
VUL-0: CVE-2019-12290: libidn2: Improper roundtrip checks when converting A-labels to U-labels
Last modified: 2020-07-10 13:35:10 UTC
CVE-2019-12290 GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By creating a malicious domain that matches a target domain except for the inclusion of certain punycoded Unicode characters (that would be discarded when converted first to a Unicode label and then back to an ASCII label), arbitrary domains can be impersonated. References: https://gitlab.com/libidn/libidn2/commit/241e8f486134793cb0f4a5b0e5817a97883401f5 https://gitlab.com/libidn/libidn2/commit/614117ef6e4c60e1950d742e3edf0a0ef8d389de https://gitlab.com/libidn/libidn2/merge_requests/71 References: https://bugzilla.redhat.com/show_bug.cgi?id=1764345 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-12290 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12290 https://gitlab.com/libidn/libidn2/commit/241e8f486134793cb0f4a5b0e5817a97883401f5 https://gitlab.com/libidn/libidn2/commit/614117ef6e4c60e1950d742e3edf0a0ef8d389de https://gitlab.com/libidn/libidn2/merge_requests/71
Tracked SUSE:SLE-15 as affected
Package changelog update sent to TW and updated version sent to SLE15.
This is an autogenerated message for OBS integration: This bug (1154884) was mentioned in https://build.opensuse.org/request/show/742496 Factory / libidn2
SUSE-SU-2019:3086-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1154884,1154887 CVE References: CVE-2019-12290,CVE-2019-18224 Sources used: SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src): libidn2-2.2.0-3.3.1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src): libidn2-2.2.0-3.3.1 SUSE Linux Enterprise Module for Basesystem 15-SP1 (src): libidn2-2.2.0-3.3.1 SUSE Linux Enterprise Module for Basesystem 15 (src): libidn2-2.2.0-3.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2019:2613-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1154884,1154887 CVE References: CVE-2019-12290,CVE-2019-18224 Sources used: openSUSE Leap 15.0 (src): libidn2-2.2.0-lp150.2.3.1
openSUSE-SU-2019:2611-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1154884,1154887 CVE References: CVE-2019-12290,CVE-2019-18224 Sources used: openSUSE Leap 15.1 (src): libidn2-2.2.0-lp151.3.3.1
Done