Updated libidn2 packages fix security vulnerabilities: It was discovered that Libidn2 incorrectly handled certain inputs. A attacker could possibly use this issue to impersonate domains (CVE-2019-12290). . MGASA-2019-0416 - Updated libidn2 packages fix security vulnerabilities Publication date: 31 Dec 2019 URL: https://advisories.mageia.org/MGASA-2019-0416.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-12290, CVE-2019-18224 Updated libidn2 packages fix security vulnerabilities: It was discovered that Libidn2 incorrectly handled certain inputs. A attacker could possibly use this issue to impersonate domains (CVE-2019-12290). It was discovered that Libidn2 incorrectly handled certain inputs. An attacker could possibly use this issue to execute arbitrary code (CVE-2019-18224). References: - https://bugs.mageia.org/show_bug.cgi?id=25652 - https://ubuntu.com/security/notices/USN-4168-1 - https://www.cve.org/CVERecord?id=CVE-2019-12290 - https://www.cve.org/CVERecord?id=CVE-2019-18224 SRPMS: - 7/core/libidn2-2.2.0-1.mga7 . Libidn2 libraries received important updates addressing security flaws related to domain impersonation and the execution of arbitrary code. For further details, click here.. libidn2, Mageia, security updates, domain security, code execution. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.