A heap-based buffer overflow vulnerability was discovered in the idn2_to_ascii_4i() function in libidn2, the GNU library for Internationalized Domain Names (IDNs), which could result in denial of service, or the execution of arbitrary code when processing a long . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4613-1
Updated libidn2 packages fix security vulnerabilities: It was discovered that Libidn2 incorrectly handled certain inputs. A attacker could possibly use this issue to impersonate domains (CVE-2019-12290). . MGASA-2019-0416 - Updated libidn2 packages fix security vulnerabilities Publication date: 31 Dec 2019 URL: https://advisories.mageia.org/MGASA-2019-0416.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-12290, CVE-2019-18224 Updated libidn2 packages fix security vulnerabilities: It was discovered that Libidn2 incorrectly handled certain inputs. A attacker could possibly use this issue to impersonate domains (CVE-2019-12290). It was discovered that Libidn2 incorrectly handled certain inputs. An attacker could possibly use this issue to execute arbitrary code (CVE-2019-18224). References: - https://bugs.mageia.org/show_bug.cgi?id=25652 - https://ubuntu.com/security/notices/USN-4168-1 - https://www.cve.org/CVERecord?id=CVE-2019-12290 - https://www.cve.org/CVERecord?id=CVE-2019-18224 SRPMS: - 7/core/libidn2-2.2.0-1.mga7 . Libidn2 libraries received important updates addressing security flaws related to domain impersonation and the execution of arbitrary code. For further details, click here.. libidn2, Mageia, security updates, domain security, code execution. . LinuxSecurity.com Team
Libidn 2.3.0 (released 2019-11-14) has assigned CVE-2019-12290 which was fixed by the roundtrip feature introduced in 2.2.0 (commit 241e8f48) * Update the data tables from Unicode 6.3.0 to Unicode 11.0 * Turn `_idn2_punycode_encode`, `_idn2_punycode_decode` into compat symbols (Fixes #74). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-160303ebeb 2019-12-09 02:27:39.934905 --------------------------------------------------------------------------------Name : libidn2 Product : Fedora 30 Version : 2.3.0 Release : 1.fc30 URL : https://www.gnu.org/software/libidn/#libidn2 Summary : Library to support IDNA2008 internationalized domain names Description : Libidn2 is an implementation of the IDNA2008 specifications in RFC 5890, 5891, 5892, 5893 and TR46 for internationalized domain names (IDN). It is a standalone library, without any dependency on libidn. --------------------------------------------------------------------------------Update Information: Libidn 2.3.0 (released 2019-11-14) ================================== * Mitre has assigned CVE-2019-12290 which was fixed by the roundtrip feature introduced in 2.2.0 (commit 241e8f48) * Update the data tables from Unicode 6.3.0 to Unicode 11.0 * Turn `_idn2_punycode_encode`, `_idn2_punycode_decode` into compat symbols (Fixes #74) --------------------------------------------------------------------------------ChangeLog: * Sat Nov 16 2019 Robert Scheck 2.3.0-1 - Upgrade to 2.3.0 (#1764345, #1772703) * Thu Jul 25 2019 Fedora Release Engineering - 2.2.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Thu May 23 2019 Robert Scheck 2.2.0-1 - Upgrade to 2.2.0 (#1713402) --------------------------------------------------------------------------------References: [ 1 ] Bug #1772703 - libidn2-2.3.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1772703 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-160303ebeb' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for libidn2 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:2611-1 Rating: moderate References: #1154884 #1154887 Cross-References: CVE-2019-12290 CVE-2019-18224 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for libidn2 to version 2.2.0 fixes the following issues: - CVE-2019-12290: Fixed an improper round-trip check when converting A-labels to U-labels (bsc#1154884). - CVE-2019-18224: Fixed a heap-based buffer overflow that was caused by long domain strings (bsc#1154887). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2019-2611=1 Package List: - openSUSE Leap 15.1 (i586 x86_64): libidn2-0-2.2.0-lp151.3.3.1 libidn2-0-debuginfo-2.2.0-lp151.3.3.1 libidn2-debugsource-2.2.0-lp151.3.3.1 libidn2-devel-2.2.0-lp151.3.3.1 libidn2-tools-2.2.0-lp151.3.3.1 libidn2-tools-debuginfo-2.2.0-lp151.3.3.1 - openSUSE Leap 15.1 (noarch): libidn2-lang-2.2.0-lp151.3.3.1 - openSUSE Leap 15.1 (x86_64): libidn2-0-32bit-2.2.0-lp151.3.3.1 libidn2-0-32bit-debuginfo-2.2.0-lp151.3.3.1 References: https://www.suse.com/security/cve/CVE-2019-12290.html https://www.suse.com/security/cve/CVE-2019-18224.html https://bugzilla.suse.com/1154884 https://bugzilla.suse.com/1154887 -- . Security Patch for openSUSE: Addresses dual vulnerabilities in libidn2, assigned amoderate severity classification. Further information available.. openSUSE Security Update, libidn2 Fixes, Moderate Severity Update. . LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for libidn2 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:2613-1 Rating: moderate References: #1154884 #1154887 Cross-References: CVE-2019-12290 CVE-2019-18224 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for libidn2 to version 2.2.0 fixes the following issues: - CVE-2019-12290: Fixed an improper round-trip check when converting A-labels to U-labels (bsc#1154884). - CVE-2019-18224: Fixed a heap-based buffer overflow that was caused by long domain strings (bsc#1154887). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-2613=1 Package List: - openSUSE Leap 15.0 (i586 x86_64): libidn2-0-2.2.0-lp150.2.3.1 libidn2-0-debuginfo-2.2.0-lp150.2.3.1 libidn2-debugsource-2.2.0-lp150.2.3.1 libidn2-devel-2.2.0-lp150.2.3.1 libidn2-tools-2.2.0-lp150.2.3.1 libidn2-tools-debuginfo-2.2.0-lp150.2.3.1 - openSUSE Leap 15.0 (x86_64): libidn2-0-32bit-2.2.0-lp150.2.3.1 libidn2-0-32bit-debuginfo-2.2.0-lp150.2.3.1 - openSUSE Leap 15.0 (noarch): libidn2-lang-2.2.0-lp150.2.3.1 References: https://www.suse.com/security/cve/CVE-2019-12290.html https://www.suse.com/security/cve/CVE-2019-18224.html https://bugzilla.suse.com/1154884 https://bugzilla.suse.com/1154887 -- . This release for libidn2 corrects vulnerabilities such as a buffer underflow andenhances general security measures.. openSUSE Update, libidn2 Security, Patch Instructions, Security Vulnerabilities. . LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for libidn2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:3086-1 Rating: moderate References: #1154884 #1154887 Cross-References: CVE-2019-12290 CVE-2019-18224 Affected Products: SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SUSE Linux Enterprise Module for Basesystem 15-SP1 SUSE Linux Enterprise Module for Basesystem 15 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for libidn2 to version 2.2.0 fixes the following issues: - CVE-2019-12290: Fixed an improper round-trip check when converting A-labels to U-labels (bsc#1154884). - CVE-2019-18224: Fixed a heap-based buffer overflow that was caused by long domain strings (bsc#1154887). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-SP1-2019-3086=1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-2019-3086=1 - SUSE Linux Enterprise Module for Basesystem 15-SP1: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP1-2019-3086=1 - SUSE Linux Enterprise Module for Basesystem 15: zypper in -t patch SUSE-SLE-Module-Basesystem-15-2019-3086=1 Package List: - SUSE Linux Enterprise Module for Open Buildservice Development Tools15-SP1 (aarch64 ppc64le s390x x86_64): libidn2-debugsource-2.2.0-3.3.1 libidn2-tools-2.2.0-3.3.1 libidn2-tools-debuginfo-2.2.0-3.3.1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (aarch64 ppc64le s390x x86_64): libidn2-debugsource-2.2.0-3.3.1 libidn2-tools-2.2.0-3.3.1 libidn2-tools-debuginfo-2.2.0-3.3.1 - SUSE Linux Enterprise Module for Basesystem 15-SP1 (aarch64 ppc64le s390x x86_64): libidn2-0-2.2.0-3.3.1 libidn2-0-debuginfo-2.2.0-3.3.1 libidn2-debugsource-2.2.0-3.3.1 libidn2-devel-2.2.0-3.3.1 - SUSE Linux Enterprise Module for Basesystem 15-SP1 (x86_64): libidn2-0-32bit-2.2.0-3.3.1 libidn2-0-32bit-debuginfo-2.2.0-3.3.1 - SUSE Linux Enterprise Module for Basesystem 15 (aarch64 ppc64le s390x x86_64): libidn2-0-2.2.0-3.3.1 libidn2-0-debuginfo-2.2.0-3.3.1 libidn2-debugsource-2.2.0-3.3.1 libidn2-devel-2.2.0-3.3.1 - SUSE Linux Enterprise Module for Basesystem 15 (x86_64): libidn2-0-32bit-2.2.0-3.3.1 libidn2-0-32bit-debuginfo-2.2.0-3.3.1 References: https://www.suse.com/security/cve/CVE-2019-12290.html https://www.suse.com/security/cve/CVE-2019-18224.html https://bugzilla.suse.com/1154884 https://bugzilla.suse.com/1154887 _______________________________________________ sle-security-updates mailing list
Libidn 2.3.0 (released 2019-11-14) has assigned CVE-2019-12290 which was fixed by the roundtrip feature introduced in 2.2.0 (commit 241e8f48) * Update the data tables from Unicode 6.3.0 to Unicode 11.0 * Turn `_idn2_punycode_encode`, `_idn2_punycode_decode` into compat symbols (Fixes #74). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-f454c7a118 2019-11-20 01:02:02.830405 --------------------------------------------------------------------------------Name : libidn2 Product : Fedora 31 Version : 2.3.0 Release : 1.fc31 URL : Summary : Library to support IDNA2008 internationalized domain names Description : Libidn2 is an implementation of the IDNA2008 specifications in RFC 5890, 5891, 5892, 5893 and TR46 for internationalized domain names (IDN). It is a standalone library, without any dependency on libidn. --------------------------------------------------------------------------------Update Information: Libidn 2.3.0 (released 2019-11-14) ================================== * Mitre has assigned CVE-2019-12290 which was fixed by the roundtrip feature introduced in 2.2.0 (commit 241e8f48) * Update the data tables from Unicode 6.3.0 to Unicode 11.0 * Turn `_idn2_punycode_encode`, `_idn2_punycode_decode` into compat symbols (Fixes #74) --------------------------------------------------------------------------------ChangeLog: * Sat Nov 16 2019 Robert Scheck 2.3.0-1 - Upgrade to 2.3.0 (#1764345, #1772703) --------------------------------------------------------------------------------References: [ 1 ] Bug #1772703 - libidn2-2.3.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1772703 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-f454c7a118' at the command line. For more information, refer to the dnf documentationavailable at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An integer overflow vulnerability was discovered in decode_digit() in libidn2-0, the GNU library for Internationalized Domain Names (IDNs), allowing a remote attacker to cause a denial of service against an application using the library (application crash). . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3988-1
Get the latest Linux and open source security news straight to your inbox.