CVE-2019-12290
Published: August 31, 2023Last modified: August 31, 2023
Description
GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By creating a malicious domain that matches a target domain except for the inclusion of certain punycoded Unicode characters (that would be discarded when converted first to a Unicode label and then back to an ASCII label), arbitrary domains can be impersonated.
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.5 |
Attack Vector | NETWORK |
Attack complexity | LOW |
Privileges required | NONE |
User interaction | NONE |
Scope | UNCHANGED |
Confidentiality | NONE |
Integrity impact | HIGH |
Availability impact | NONE |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Status
Product | Release | Package | Status |
---|---|---|---|
Alpaquita Linux | 23 LTS | libidn2 | Not affected (2.3.4-r0) |
Stream | libidn2 | Not affected (2.3.4-r2) |
References
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00009.html
- https://gitlab.com/libidn/libidn2/commit/241e8f486134793cb0f4a5b0e5817a97883401f5
- https://gitlab.com/libidn/libidn2/commit/614117ef6e4c60e1950d742e3edf0a0ef8d389de
- https://gitlab.com/libidn/libidn2/merge_requests/71
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFT76Y7OSGPZV3EBEHD6ISVUM3DLARM/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KXDKYWFV6N2HHVSE67FFDM7G3FEL2ZNE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ONG3GJRRJO35COPGVJXXSZLU4J5Y42AT/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RSI4TI2JTQWQ3YEUX5X36GTVGKO4QKZ5/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U6ZXL2RDNQRAHCMKWPOMJFKYJ344X4HL/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/3UFT76Y7OSGPZV3EBEHD6ISVUM3DLARM/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/KXDKYWFV6N2HHVSE67FFDM7G3FEL2ZNE/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/ONG3GJRRJO35COPGVJXXSZLU4J5Y42AT/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/RSI4TI2JTQWQ3YEUX5X36GTVGKO4QKZ5/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/U6ZXL2RDNQRAHCMKWPOMJFKYJ344X4HL/
- https://security.gentoo.org/glsa/202003-63
- https://usn.ubuntu.com/4168-1/