Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-12224

Опубликовано: 30 мая 2025
Источник: debian

Описание

Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rust-idnafixed1.0.3-1experimentalpackage
rust-idnafixed1.0.3-2package
rust-idnano-dsabookwormpackage
rust-idnapostponedbullseyepackage

Примечания

  • https://rustsec.org/advisories/RUSTSEC-2024-0421.html

  • https://bugzilla.mozilla.org/show_bug.cgi?id=1887898

Связанные уязвимости

CVSS3: 8.8
ubuntu
8 месяцев назад

Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.

CVSS3: 4.2
redhat
8 месяцев назад

Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.

CVSS3: 8.8
nvd
8 месяцев назад

Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.

suse-cvrf
16 дней назад

Security update for librsvg

suse-cvrf
6 месяцев назад

Security update for sccache