Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 40: 2024-098b5d9719 Moderate: Python-idna DoS Risk Advisory

fedora
Calendar Grey April 29, 2024
Dist Fedora Esm H88
The latest version of python-idna, 3.7, introduces a security patch addressing CVE-2024-3651, which poses a DoS threat in Fedora 40 environments.
Update to 3.7 (rhbz#2274439), security fix for CVE-2024-3651

Summary

A library to support the Internationalised Domain Names in Applications (IDNA)

protocol as specified in RFC 5891 . This

version of the protocol is often referred to as "IDNA2008" and can produce

different results from the earlier standard from 2003.

The library is also intended to act as a suitable drop-in replacement for the

"encodings.idna" module that comes with the Python standard library but

currently only supports the older 2003 specification.

Update Information:

Update to 3.7 (rhbz#2274439), security fix for CVE-2024-3651

Change Log

* Thu Apr 11 2024 Lumir Balhar - 3.7-1 - Update to 3.7 (rhbz#2274439)

References


[ 1 ] Bug #2274439 - python-idna-3.7 is available https://bugzilla.redhat.com/show_bug.cgi?id=2274439 [ 2 ] Bug #2274780 - TRIAGE CVE-2024-3651 python-idna: potential DoS via resource consumption via specially crafted inputs to idna.encode() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2274780

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-098b5d9719' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: python-idna
Product: Fedora 40
Version: 3.7
Release: 1.fc40
Summary: Internationalized Domain Names in Applications (IDNA)

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here