Logo
vulnerabilityCVE-2024-3651
Name
CVE-2024-3651
Source
NVD ( link)Debian ( link)
Description
A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's handling of crafted input strings, which can lead to quadratic complexity and consequently, a denial of service condition. This vulnerability is triggered by a crafted input that causes the `idna.encode()` function to process the input with considerable computational load, significantly increasing the processing time in a quadratic manner relative to the input size.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
python3-idna
Patched

Vulnerability Ratings#


7.5
CVSSv31
6.2
other
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
3.18
Not Affected
yocto
scarthgap
3.7
Not Affected

Resolved with patches#


python3-idna (yocto:kirkstone)

#
Title
Author
Resolve
1
More efficient resolution of joiner contexts
Kim Davies <kim@cynosure.com.au>
CVE-2024-3651