idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libidn2 | Aug 22, 2024 | Oct 21, 2019 |
| Amazon Linux Ami 2 | — | Upgrade idn2Upgrade libidn2-develUpgrade libidn2-debuginfoUpgrade libidn2 | Apr 27, 2020 | Oct 21, 2019 |
| Amazon_linux | — | Upgrade libidn2 | Dec 20, 2019 | Oct 21, 2019 |
| Debian | — | Upgrade libidn2 | Feb 3, 2020 | Oct 21, 2019 |
| Gentoo Linux | — | Upgrade net-dns/libidn2. | Mar 31, 2020 | Oct 21, 2019 |
| Oracle Solaris | — | Upgrade library/libidn2 to version 2.0.4-11.4.16.0.1.3.0 on Solaris 11.4Upgrade consolidation/userland/userland-incorporation to version 0.5.11-0.175.3.36.0.27.0 on Solaris 11.3 | Dec 18, 2019 | Oct 21, 2019 |
| Suse | — | Upgrade libidn2-develUpgrade libidn2-0Upgrade libidn2-langUpgrade libidn2-0-32bitUpgrade libidn2-tools | Dec 5, 2019 | Oct 21, 2019 |
| Ubuntu | — | Upgrade libidn2-0Upgrade idn2 | Oct 30, 2019 | Oct 21, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub