Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Mageia 7: MGASA-2019-0416 Moderate: Libidn2 Code Execution Flaws

mageia
Calendar Grey December 31, 2019
Dist Mageia Esm H88
Libidn2 libraries received important updates addressing security flaws related to domain impersonation and the execution of arbitrary code. For further details, click here.
Updated libidn2 packages fix security vulnerabilities: It was discovered that Libidn2 incorrectly handled certain inputs

Summary

Updated libidn2 packages fix security vulnerabilities:
It was discovered that Libidn2 incorrectly handled certain inputs. A attacker could possibly use this issue to impersonate domains (CVE-2019-12290).
It was discovered that Libidn2 incorrectly handled certain inputs. An attacker could possibly use this issue to execute arbitrary code (CVE-2019-18224).

References

- https://bugs.mageia.org/show_bug.cgi?id=25652

- https://ubuntu.com/security/notices/USN-4168-1

- https://www.cve.org/CVERecord?id=CVE-2019-12290

- https://www.cve.org/CVERecord?id=CVE-2019-18224

Resolution

SRPMS

- 7/core/libidn2-2.2.0-1.mga7

Publication date: 31 Dec 2019
URL: https://advisories.mageia.org/MGASA-2019-0416.html
Type: security
CVE: CVE-2019-12290, CVE-2019-18224

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here