CVE-2019-15237: High severity roundcube vulnerability
Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-15237?
CVE-2019-15237 is a vulnerability in Roundcube Webmail through version 1.3.9 that mishandles Punycode xn-- domain names, leading to homograph attacks.
How does CVE-2019-15237 affect Roundcube Webmail?
CVE-2019-15237 affects Roundcube Webmail versions up to and including 1.3.9.
What is a Punycode xn-- domain name?
A Punycode xn-- domain name is an internationalized domain name (IDN) represented with ASCII characters, allowing homograph attacks.
What is a homograph attack?
A homograph attack is a type of phishing attack where a malicious actor uses visually similar characters from different character sets to create a domain that appears identical to a legitimate domain.
Are there any mitigations or patches available for CVE-2019-15237?
At the time of this writing, no official patches or mitigations have been released for CVE-2019-15237. It is recommended to update to a fixed version when it becomes available.