CVE-2019-12290
published 2019-10-22CVE-2019-12290: GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
2.79%
84.7th percentile
GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By creating a malicious domain that matches a target domain except for the inclusion of certain punycoded Unicode characters (that would be discarded when converted first to a Unicode label and then back to an ASCII label), arbitrary domains can be impersonated.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libidn2 | < libidn2 2.2.0-1 (bookworm) | libidn2 2.2.0-1 (bookworm) |
| gnu | libidn2 | < 2.2.0 | 2.2.0 |
| gnu | libidn2 | >= 0 < 2.2.0-1 | 2.2.0-1 |
| gnu | libidn2 | >= 0 < 2.2.0-1 | 2.2.0-1 |
| gnu | libidn2 | >= 0 < 2.2.0-1 | 2.2.0-1 |
| gnu | libidn2 | >= 0 < 2.2.0-1 | 2.2.0-1 |
| gnu | libidn2 | >= 0 < 2.0.4-1.1ubuntu0.2 | 2.0.4-1.1ubuntu0.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5pjp-55fh-7frw: GNU libidn2 before 2
ghsa_unreviewed·2022-05-24
CVE-2019-12290 [HIGH] CWE-20 GHSA-5pjp-55fh-7frw: GNU libidn2 before 2
GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By creating a malicious domain that matches a target domain except for the inclusion of certain punycoded Unicode characters (that would be discarded when converted first to a Unicode label and then back to an ASCII label), arbitrary domains can be impersonated.
OSV
libidn2 vulnerabilities
osv·2019-10-29·CVSS 7.5
CVE-2019-12290 [HIGH] libidn2 vulnerabilities
libidn2 vulnerabilities
It was discovered that Libidn2 incorrectly handled certain inputs.
A attacker could possibly use this issue to impersonate domains.
(CVE-2019-12290)
It was discovered that Libidn2 incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2019-18224)
OSV
CVE-2019-12290: GNU libidn2 before 2
osv·2019-10-22·CVSS 7.5
CVE-2019-12290 [HIGH] CVE-2019-12290: GNU libidn2 before 2
GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By creating a malicious domain that matches a target domain except for the inclusion of certain punycoded Unicode characters (that would be discarded when converted first to a Unicode label and then back to an ASCII label), arbitrary domains can be impersonated.
Ubuntu
Libidn2 vulnerabilities
vendor_ubuntu·2019-10-29·CVSS 7.5
CVE-2019-12290 [HIGH] Libidn2 vulnerabilities
Title: Libidn2 vulnerabilities
Summary: Several security issues were fixed in Libidn2.
It was discovered that Libidn2 incorrectly handled certain inputs.
A attacker could possibly use this issue to impersonate domains.
(CVE-2019-12290)
It was discovered that Libidn2 incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2019-18224)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-12290: libidn2 - GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3...
vendor_debian·2019·CVSS 7.5
CVE-2019-12290 [HIGH] CVE-2019-12290: libidn2 - GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3...
GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By creating a malicious domain that matches a target domain except for the inclusion of certain punycoded Unicode characters (that would be discarded when converted first to a Unicode label and then back to an ASCII label), arbitrary domains can be impersonated.
Scope: local
bookworm: resolved (fixed in 2.2.0-1)
bullseye: resolved (fixed in 2.2.0-1)
forky: resolved (fixed in 2.2.0-1)
sid: resolved (fixed in 2.2.0-1)
trixie: resolved (fixed in 2.2.0-1)
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-12/msg00009.htmlhttps://gitlab.com/libidn/libidn2/commit/241e8f486134793cb0f4a5b0e5817a97883401f5https://gitlab.com/libidn/libidn2/commit/614117ef6e4c60e1950d742e3edf0a0ef8d389dehttps://gitlab.com/libidn/libidn2/merge_requests/71https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFT76Y7OSGPZV3EBEHD6ISVUM3DLARM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KXDKYWFV6N2HHVSE67FFDM7G3FEL2ZNE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ONG3GJRRJO35COPGVJXXSZLU4J5Y42AT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RSI4TI2JTQWQ3YEUX5X36GTVGKO4QKZ5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U6ZXL2RDNQRAHCMKWPOMJFKYJ344X4HL/https://security.gentoo.org/glsa/202003-63https://usn.ubuntu.com/4168-1/http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-12/msg00009.htmlhttps://gitlab.com/libidn/libidn2/commit/241e8f486134793cb0f4a5b0e5817a97883401f5https://gitlab.com/libidn/libidn2/commit/614117ef6e4c60e1950d742e3edf0a0ef8d389dehttps://gitlab.com/libidn/libidn2/merge_requests/71https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFT76Y7OSGPZV3EBEHD6ISVUM3DLARM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KXDKYWFV6N2HHVSE67FFDM7G3FEL2ZNE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ONG3GJRRJO35COPGVJXXSZLU4J5Y42AT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RSI4TI2JTQWQ3YEUX5X36GTVGKO4QKZ5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U6ZXL2RDNQRAHCMKWPOMJFKYJ344X4HL/https://security.gentoo.org/glsa/202003-63https://usn.ubuntu.com/4168-1/
2019-10-22
Published