First published: Tue Aug 20 2019(Updated: )
Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Roundcube Webmail | <=1.3.9 | |
Fedoraproject Fedora | =29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15237 is a vulnerability in Roundcube Webmail through version 1.3.9 that mishandles Punycode xn-- domain names, leading to homograph attacks.
CVE-2019-15237 affects Roundcube Webmail versions up to and including 1.3.9.
A Punycode xn-- domain name is an internationalized domain name (IDN) represented with ASCII characters, allowing homograph attacks.
A homograph attack is a type of phishing attack where a malicious actor uses visually similar characters from different character sets to create a domain that appears identical to a legitimate domain.
At the time of this writing, no official patches or mitigations have been released for CVE-2019-15237. It is recommended to update to a fixed version when it becomes available.