Bugzilla – Bug 1154887
VUL-0: CVE-2019-18224: libidn2: heap-based buffer overflow via a long domain string
Last modified: 2020-07-10 13:35:25 UTC
CVE-2019-18224 idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-18224 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=12420 http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-18224.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18224 https://github.com/libidn/libidn2/commit/e4d1558aa2c1c04a05066ee8600f37603890ba8c https://github.com/libidn/libidn2/compare/libidn2-2.1.0...libidn2-2.1.1
Tracked SLE15 as affected
Package changelog update sent to TW and updated version sent to SLE15.
This is an autogenerated message for OBS integration: This bug (1154887) was mentioned in https://build.opensuse.org/request/show/742496 Factory / libidn2
SUSE-SU-2019:3086-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1154884,1154887 CVE References: CVE-2019-12290,CVE-2019-18224 Sources used: SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src): libidn2-2.2.0-3.3.1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src): libidn2-2.2.0-3.3.1 SUSE Linux Enterprise Module for Basesystem 15-SP1 (src): libidn2-2.2.0-3.3.1 SUSE Linux Enterprise Module for Basesystem 15 (src): libidn2-2.2.0-3.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2019:2613-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1154884,1154887 CVE References: CVE-2019-12290,CVE-2019-18224 Sources used: openSUSE Leap 15.0 (src): libidn2-2.2.0-lp150.2.3.1
openSUSE-SU-2019:2611-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1154884,1154887 CVE References: CVE-2019-12290,CVE-2019-18224 Sources used: openSUSE Leap 15.1 (src): libidn2-2.2.0-lp151.3.3.1
Done