You are here
Home > Preporuke > Sigurnosni nedostaci programske biblioteke libidn2

Sigurnosni nedostaci programske biblioteke libidn2

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-4168-1
October 29, 2019

libidn2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 19.04
– Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in Libidn2.

Software Description:
– libidn2: Internationalized domain names (IDNA2008/TR46) command line tool

Details:

It was discovered that Libidn2 incorrectly handled certain inputs.
A attacker could possibly use this issue to impersonate domains.
(CVE-2019-12290)

It was discovered that Libidn2 incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2019-18224)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.04:
idn2 2.0.5-1ubuntu0.3
libidn2-0 2.0.5-1ubuntu0.3

Ubuntu 18.04 LTS:
idn2 2.0.4-1.1ubuntu0.2
libidn2-0 2.0.4-1.1ubuntu0.2

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4168-1
CVE-2019-12290, CVE-2019-18224

Package Information:
https://launchpad.net/ubuntu/+source/libidn2/2.0.5-1ubuntu0.3
https://launchpad.net/ubuntu/+source/libidn2/2.0.4-1.1ubuntu0.2
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1

iQIcBAEBAgAGBQJduE8/AAoJEEW851uECx9p7JMQAKGWiy8FqS4aKphZygIQfurL
pCtOMJYwN58+1ftoEl2EzpdQHKXhe6yKsZkTHJJfP3veGesfQFXpxWxE0cQuZxEz
W5tNsQ2OQJg9wWOk63jyo2ezrW14AuRw4/VtYmeJ3IlqV2S2XSj3epSNqAwSJIzn
hDjIRN2r6E4BoMJR2VwgxplW921tVXxW7Sa1mD+RMhVRKKgRgCND6crT5nGi6lVq
xOs5RlAoGv0oh978vj7rHPSmgAdzTKmAyAerzqurbgUyTzIbqNSbBQMfcsS40hQ/
MzttKXmEIjN5xMaYXpHBamVYvVxDuwkY9kxKA98fic3wXF0pArig6ox8ytkgLg7h
uoQvPIQsWBdHiIVzU7azPBENtqQqVVX9OutTBwZuf6XFQzARkmSxVHTjIU6lqWxp
qGkh6Lr0XcetZU2gTKzYBgr7Zuygl+fdoJkBhmvMy2FQVDYMHl8AXaqORVOclPMQ
0ib9/0Crjepkw9k+E0CMkcxT50e7Sv0NmLh6aIFs/wiEU1XszaITJolgNz7iKfCa
XVLmIpL3zs/9kECM22q/zbjTDip+HRMdPjPn7VuQHxE+bc2RAsE9BTSjTKd8aBf4
6tpcmHreBQNlJuhq5GjGOVv3ruqC9yVyGZECKMJ7bVkIduBYhLx4TmMZgbaBOPDH
FHCXK+6W2J9XVW7LOSwe
=z9ot
—–END PGP SIGNATURE—–

AutorToni Vugdelija
Cert idNCERT-REF-2019-10-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostatak programskog paketa php

Otkriven je sigurnosni nedostatak u programskom paketu php za operacijski sustav Ubuntu. Otkriveni nedostatak potencijalnim udaljenim napadačima omogućuje izvršavanje proizvoljnog...

Close