Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-3651

Опубликовано: 12 апр. 2024
Источник: redhat
CVSS3: 6.5

Описание

A vulnerability was identified in the kjd/idna library, specifically within the idna.encode() function, affecting version 3.6. The issue arises from the function's handling of crafted input strings, which can lead to quadratic complexity and consequently, a denial of service condition. This vulnerability is triggered by a crafted input that causes the idna.encode() function to process the input with considerable computational load, significantly increasing the processing time in a quadratic manner relative to the input size.

A flaw was found in the python-idna library. A malicious argument was sent to the idna.encode() function can trigger an uncontrolled resource consumption, resulting in a denial of service.

Отчет

The vulnerability in the idna.encode() function, allowing for resource consumption via specially crafted arguments, is categorized as a moderate severity issue due to its potential impact on system availability rather than data integrity or confidentiality. While the vulnerability can lead to a denial-of-service condition, it requires the passing of unusually large or maliciously crafted inputs to exploit. Normal usage scenarios typically do not encounter such inputs.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10python-idnaNot affected
Red Hat Enterprise Linux 8python27:2.7/python-idnaWill not fix
Red Hat OpenShift Container Platform 3.11python-idnaOut of support scope
Red Hat Satellite 6ansiblerole-foreman_scap_clientAffected
Red Hat Satellite 6python-idnaAffected
Red Hat Satellite 6python-idna-sslAffected
Red Hat Software Collectionsrh-python38-python-idnaNot affected
Red Hat Update Infrastructure 4 for Cloud Providerspython-idnaWill not fix
Red Hat Update Infrastructure 4 for Cloud Providerspython-idna-sslWill not fix
Red Hat Ansible Automation Platform 2.4 for RHEL 8python3x-idnaFixedRHSA-2024:378110.06.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2274779python-idna: potential DoS via resource consumption via specially crafted inputs to idna.encode()

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
12 месяцев назад

A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's handling of crafted input strings, which can lead to quadratic complexity and consequently, a denial of service condition. This vulnerability is triggered by a crafted input that causes the `idna.encode()` function to process the input with considerable computational load, significantly increasing the processing time in a quadratic manner relative to the input size.

CVSS3: 7.5
nvd
12 месяцев назад

A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's handling of crafted input strings, which can lead to quadratic complexity and consequently, a denial of service condition. This vulnerability is triggered by a crafted input that causes the `idna.encode()` function to process the input with considerable computational load, significantly increasing the processing time in a quadratic manner relative to the input size.

CVSS3: 7.5
msrc
10 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
12 месяцев назад

A vulnerability was identified in the kjd/idna library, specifically w ...

suse-cvrf
около 1 года назад

Security update for python-idna

6.5 Medium

CVSS3