GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By creating a malicious domain that matches a target domain except for the inclusion of certain punycoded Unicode characters (that would be discarded when converted first to a Unicode label and then back to an ASCII label), arbitrary domains can be impersonated.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libidn2 | Aug 22, 2024 | Oct 22, 2019 |
| Amazon Linux Ami 2 | — | Upgrade libidn2-develUpgrade libidn2Upgrade libidn2-debuginfoUpgrade idn2 | Apr 27, 2020 | Oct 22, 2019 |
| Amazon_linux | — | Upgrade libidn2 | Dec 20, 2019 | Oct 22, 2019 |
| Debian | — | Upgrade libidn2 | Jul 30, 2024 | Oct 22, 2019 |
| Freebsd | — | Upgrade libidn2 | Nov 19, 2019 | Nov 18, 2019 |
| Gentoo Linux | — | Upgrade net-dns/libidn2. | Mar 31, 2020 | Oct 22, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade libidn2 | Feb 26, 2020 | Oct 22, 2019 |
| Oracle Solaris | — | Upgrade consolidation/userland/userland-incorporation to version 0.5.11-0.175.3.36.0.27.0 on Solaris 11.3Upgrade library/libidn2 to version 2.0.4-11.4.16.0.1.3.0 on Solaris 11.4 | Dec 18, 2019 | Oct 22, 2019 |
| Suse | — | Upgrade libidn2-develUpgrade libidn2-toolsUpgrade libidn2-0-32bitUpgrade libidn2-langUpgrade libidn2-0 | Dec 5, 2019 | Oct 22, 2019 |
| Ubuntu | — | Upgrade idn2Upgrade libidn2-0 | Oct 30, 2019 | Oct 22, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub