From fdc2753f693612f62336ebbfc95beb916b90ec41 Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Tue, 16 Apr 2024 21:42:07 +0200 Subject: Add Debian bug reference for CVE-2024-3651/python-idna --- data/CVE/list | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/data/CVE/list b/data/CVE/list index ff133fbf1e..fa5d97f06b 100644 --- a/data/CVE/list +++ b/data/CVE/list @@ -626,7 +626,7 @@ CVE-2023-52144 (Improper Limitation of a Pathname to a Restricted Directory ('Pa CVE-2024-3508 NOT-FOR-US: Bombastic's use of bzip2 CVE-2024-3651 [potential DoS via resource consumption via specially crafted inputs to idna.encode()] - - python-idna + - python-idna (bug #1069127) NOTE: https://github.com/kjd/idna/security/advisories/GHSA-jjg7-2v4v-x38h NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2274779 NOTE: Fixed by: https://github.com/kjd/idna/commit/5beb28b9dd77912c0dd656d8b0fdba3eb80222e7 (v3.7) -- cgit v1.2.3