Impersonation Vulnerability in GNU libidn2 Affects Domain Name Conversion
CVE-2019-12290

7.5HIGH

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
22 October 2019

Summary

A vulnerability in GNU libidn2 prior to version 2.2.0 allows attackers to impersonate arbitrary domains. This is achieved through insufficient validation checks during the conversion process from A-labels to U-labels as outlined in RFC3490 Section 4.2. By leveraging punycoded Unicode characters, an attacker can craft a malicious domain that appears similar to a legitimate domain. When these domains undergo the conversion process to Unicode labels and back to ASCII, certain characters may be discarded, facilitating the impersonation without triggering security measures.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.