Описание
A vulnerability was identified in the kjd/idna library, specifically within the idna.encode() function, affecting version 3.6. The issue arises from the function's handling of crafted input strings, which can lead to quadratic complexity and consequently, a denial of service condition. This vulnerability is triggered by a crafted input that causes the idna.encode() function to process the input with considerable computational load, significantly increasing the processing time in a quadratic manner relative to the input size.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 3.6-2.1 |
| esm-infra/bionic | released | 2.6-1ubuntu0.1~esm1 |
| esm-infra/focal | released | 2.8-1ubuntu0.1 |
| esm-infra/xenial | released | 2.0-3ubuntu0.1~esm1 |
| focal | released | 2.8-1ubuntu0.1 |
| jammy | released | 3.3-1ubuntu0.1 |
| mantic | released | 3.3-2ubuntu0.1 |
| noble | released | 3.6-2ubuntu0.1 |
| oracular | not-affected | 3.6-2.1 |
| plucky | not-affected | 3.6-2.1 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 25.1.1+dfsg-1 |
| esm-apps/bionic | released | 9.0.1-2.3~ubuntu1.18.04.8+esm4 |
| esm-apps/focal | released | 20.0.2-5ubuntu1.10+esm2 |
| esm-apps/jammy | released | 22.0.2+dfsg-1ubuntu0.7 |
| esm-apps/noble | released | 24.0+dfsg-1ubuntu1.3 |
| esm-apps/xenial | released | 8.1.1-2ubuntu0.6+esm8 |
| esm-infra-legacy/trusty | not-affected | code not present |
| focal | ignored | end of standard support, was needs-triage |
| jammy | released | 22.0.2+dfsg-1ubuntu0.7 |
| mantic | ignored | end of life, was needs-triage |
Показывать по
EPSS
7.5 High
CVSS3
Связанные уязвимости
A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's handling of crafted input strings, which can lead to quadratic complexity and consequently, a denial of service condition. This vulnerability is triggered by a crafted input that causes the `idna.encode()` function to process the input with considerable computational load, significantly increasing the processing time in a quadratic manner relative to the input size.
A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's handling of crafted input strings, which can lead to quadratic complexity and consequently, a denial of service condition. This vulnerability is triggered by a crafted input that causes the `idna.encode()` function to process the input with considerable computational load, significantly increasing the processing time in a quadratic manner relative to the input size.
A vulnerability was identified in the kjd/idna library, specifically w ...
EPSS
7.5 High
CVSS3