Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-12290

Опубликовано: 22 окт. 2019
Источник: debian
EPSS Низкий

Описание

GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By creating a malicious domain that matches a target domain except for the inclusion of certain punycoded Unicode characters (that would be discarded when converted first to a Unicode label and then back to an ASCII label), arbitrary domains can be impersonated.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libidn2fixed2.2.0-1package
libidn2no-dsabusterpackage

Примечания

  • https://gitlab.com/libidn/libidn2/commit/241e8f486134793cb0f4a5b0e5817a97883401f5 (2.2.0)

  • https://gitlab.com/libidn/libidn2/merge_requests/71

  • Backport available: https://git.launchpad.net/ubuntu/+source/libidn2/commit/?id=0aa447342fbf0fc37d7887982e0daf817db08b1d

EPSS

Процентиль: 86%
0.02892
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By creating a malicious domain that matches a target domain except for the inclusion of certain punycoded Unicode characters (that would be discarded when converted first to a Unicode label and then back to an ASCII label), arbitrary domains can be impersonated.

CVSS3: 7.5
nvd
больше 6 лет назад

GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By creating a malicious domain that matches a target domain except for the inclusion of certain punycoded Unicode characters (that would be discarded when converted first to a Unicode label and then back to an ASCII label), arbitrary domains can be impersonated.

CVSS3: 7.5
github
больше 3 лет назад

GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By creating a malicious domain that matches a target domain except for the inclusion of certain punycoded Unicode characters (that would be discarded when converted first to a Unicode label and then back to an ASCII label), arbitrary domains can be impersonated.

CVSS3: 7.5
fstec
около 6 лет назад

Уязвимость компонента RFC3490 библиотеки Libidn2, позволяющая нарушителю создать вредоносный домен, который соответствует целевому домену

suse-cvrf
около 6 лет назад

Security update for libidn2

EPSS

Процентиль: 86%
0.02892
Низкий