CVE-2019-18224

idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:libidn2:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:06

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MINU5RKDFE6TKAFY5DRFN3WSFDS4DYVS/', 'name': 'FEDORA-2019-d3221d69e0', 'tags': [], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JDQVQ2XPV5BTZUFINT7AFJSKNNBVURNJ/', 'name': 'FEDORA-2019-a8d35fcf7c', 'tags': [], 'refsource': 'FEDORA'}
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MINU5RKDFE6TKAFY5DRFN3WSFDS4DYVS/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JDQVQ2XPV5BTZUFINT7AFJSKNNBVURNJ/ -

Information

Published : 2019-10-21 17:15

Updated : 2023-12-10 13:13


NVD link : CVE-2019-18224

Mitre link : CVE-2019-18224

CVE.ORG link : CVE-2019-18224


JSON object : View

Products Affected

gnu

  • libidn2
CWE
CWE-787

Out-of-bounds Write