Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-12224

Опубликовано: 30 мая 2025
Источник: debian
EPSS Низкий

Описание

Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rust-idnafixed1.0.3-1experimentalpackage
rust-idnafixed1.0.3-2package
rust-idnano-dsabookwormpackage
rust-idnapostponedbullseyepackage

Примечания

  • https://rustsec.org/advisories/RUSTSEC-2024-0421.html

  • https://bugzilla.mozilla.org/show_bug.cgi?id=1887898

EPSS

Процентиль: 11%
0.00213
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 1 года назад

Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.

CVSS3: 5.9
redhat
около 1 года назад

Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.

CVSS3: 8.8
nvd
около 1 года назад

Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.

suse-cvrf
7 месяцев назад

Security update for librsvg

suse-cvrf
около 1 года назад

Security update for sccache

EPSS

Процентиль: 11%
0.00213
Низкий