Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 30: FEDORA-2019-160303ebeb Moderate: libidn2 CVE Fix

fedora
Calendar Grey December 8, 2019
Dist Fedora Esm H88
The latest update for Libidn2 on Fedora addresses a crucial security vulnerability, significantly improving its handling of international domain names and overall Unicode functionality.
Libidn 2.3.0 (released 2019-11-14) has assigned CVE-2019-12290 which was fixed by the roundtrip feature introduced in 2.2.0 (commit 241e8f48) * Update the data tables from Unicode ...

Summary

Libidn2 is an implementation of the IDNA2008 specifications in RFC

5890, 5891, 5892, 5893 and TR46 for internationalized domain names

(IDN). It is a standalone library, without any dependency on libidn.

Libidn 2.3.0 (released 2019-11-14) ================================== * Mitre

has assigned CVE-2019-12290 which was fixed by the roundtrip feature introduced

in 2.2.0 (commit 241e8f48) * Update the data tables from Unicode 6.3.0 to

Unicode 11.0 * Turn `_idn2_punycode_encode`, `_idn2_punycode_decode` into

compat symbols (Fixes #74)

* Sat Nov 16 2019 Robert Scheck 2.3.0-1

- Upgrade to 2.3.0 (#1764345, #1772703)

* Thu Jul 25 2019 Fedora Release Engineering - 2.2.0-2

- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild

* Thu May 23 2019 Robert Scheck 2.2.0-1

- Upgrade to 2.2.0 (#1713402)

[ 1 ] Bug #1772703 - libidn2-2.3.0 is available

https://bugzilla.redhat.com/show_bug.cgi?id=1772703

su -c 'dnf upgrade --advisory FEDORA-2019-160303ebeb' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 30
Version: 2.3.0
Release: 1.fc30
Summary: Library to support IDNA2008 internationalized domain names

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here