CVE-2019-9970
Last modified
CVE-2019-9970 is a vulnerability of currently unknown severity. Open Whisper Signal (aka Signal-Desktop) through 1.23.1 and the Signal Private Messenger application through 4.35.3 for Android are vulnerable to an IDN homograph attack when displaying messages containing URLs. This occurs because the application produces a clickable link even if (for example) Latin and Cyrillic characters exist in the same domain name, and the available font has an identical representation of characters from different alphabets.. EPSS estimates a 1.83% chance of exploitation in the next 30 days.
Description
Open Whisper Signal (aka Signal-Desktop) through 1.23.1 and the Signal Private Messenger application through 4.35.3 for Android are vulnerable to an IDN homograph attack when displaying messages containing URLs. This occurs because the application produces a clickable link even if (for example) Latin and Cyrillic characters exist in the same domain name, and the available font has an identical representation of characters from different alphabets.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Signal | Private Messenger | <= 4.35.3 |
| Signal | Signal-Desktop | <= 1.23.1 |
References
- http://www.securityfocus.com/bid/107550Third Party Advisory, VDB Entry
- https://github.com/blazeinfosec/advisories/blob/master/signal-advisory.txtThird Party Advisory
- http://www.securityfocus.com/bid/107550Third Party Advisory, VDB Entry
- https://github.com/blazeinfosec/advisories/blob/master/signal-advisory.txtThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-9970?
How severe is CVE-2019-9970?
How do I fix CVE-2019-9970?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-9964XnView MP 0.93.1 on Windows allows remote attackers to cause…
- CVE-2019-9965XnView MP 0.93.1 on Windows allows remote attackers to cause…
- CVE-2019-9966XnView Classic 2.48 on Windows allows remote attackers to ca…
- CVE-2019-9967XnView Classic 2.48 on Windows allows remote attackers to ca…
- CVE-2019-9968XnView Classic 2.48 on Windows allows remote attackers to ca…
- CVE-2019-9969XnView Classic 2.48 on Windows allows remote attackers to ca…
- CVE-2019-9971PhoneSystem Terminal in 3CX Phone System (Debian based insta…8.8
- CVE-2019-9972PhoneSystem Terminal in 3CX Phone System (Debian based insta…8.8
- CVE-2019-9974diag_tool.cgi on DASAN H660RM GPON routers with firmware 1.0…
- CVE-2019-9975DASAN H660RM devices with firmware 1.03-0022 use a hard-code…
- CVE-2019-9976The Boa server configuration on DASAN H660RM devices with fi…
- CVE-2019-9977The renderer process in the entertainment system on Tesla Mo…
Are you affected by CVE-2019-9970?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
