Download
| Alert*
oval:org.secpod.oval:def:89050867
This update for libidn2 to version 2.2.0 fixes the following issues: - CVE-2019-12290: Fixed an improper round-trip check when converting A-labels to U-labels . - CVE-2019-18224: Fixed a heap-based buffer overflow that was caused by long domain strings . oval:org.secpod.oval:def:1601085 idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string. GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances f ... oval:org.secpod.oval:def:2105274 GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By creating a malicious domain that matches a target domain except for the inclusi ... oval:org.secpod.oval:def:705256 libidn2: Internationalized domain names command line tool Several security issues were fixed in Libidn2. oval:org.secpod.oval:def:59607 libidn2: Internationalized domain names command line tool Several security issues were fixed in Libidn2. oval:org.secpod.oval:def:1700285 heap-based buffer overflow in idn2_to_ascii_4i in lib/lookup.c idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string. |