CVE-2019-18224
Description
RHBA-2019:3621: libidn2 bug fix and enhancement update (Moderate)
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
Description libidn2: heap-based buffer overflow in idn2_to_ascii_4i in lib/lookup.c CVSS v3: 5.6 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 8libidn2-0:2.2.0-1.el8RHBA-2019:36212019-11-05T00:00:00Z Red Hat Enterprise Linux 8libidn2-0:2.2.0-1.el8RHBA-2019:36212019-11-05T00:00:00Z
Description
libidn2: heap-based buffer overflow in idn2_to_ascii_4i in lib/lookup.c
CVSS v3: 5.6 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
Errata / fixed releases
| Product | Package | Advisory | Released |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | libidn2-0:2.2.0-1.el8 | RHBA-2019:3621 | 2019-11-05T00:00:00Z |
| Red Hat Enterprise Linux 8 | libidn2-0:2.2.0-1.el8 | RHBA-2019:3621 | 2019-11-05T00:00:00Z |
Apply commands
yum update -y libidn2
# or:
dnf upgrade -y libidn2
OS impact
SUSE Affected 1 release
| Version | Status | Fixed in |
|---|---|---|
| โ | Affected | โ |
Debian Fixed 5 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Fixed | 2.2.0-1 |
| sid | Fixed | 2.2.0-1 |
| forky | Fixed | 2.2.0-1 |
| bullseye | Fixed | 2.2.0-1 |
| bookworm | Fixed | 2.2.0-1 |
Red Hat Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 8 | Fixed | โ |
Rocky Linux Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 8 | Fixed | โ |
References
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.