New Debian python-idna 2.6-1+deb10u1 fixes: This update addresses the following issue: Debian update 2.6-1+deb10u1 2.6-1+deb10u1 (Wed, 08 May 2024 17:57:07 +0200) * Non-maintainer upload by the LTS Security Team. * Fix CVE-2024-3651: Specially crafted inputs to idna.encode() can consume significant resources, which may lead to denial of service.
--- mirror/ftp/pool/main/p/python-idna/python-idna_2.6-1.dsc +++ apt/ucs_5.0-0-errata5.0-7/source/python-idna_2.6-1+deb10u1.dsc @@ -1,3 +1,10 @@ +2.6-1+deb10u1 [Wed, 08 May 2024 17:57:07 +0200] Guilhem Moulin <guilhem@debian.org>: + + * Non-maintainer upload by the LTS Security Team. + * Fix CVE-2024-3651: Specially crafted inputs to idna.encode() can consume + significant resources, which may lead to denial of service. + (Closes: #1069127) + 2.6-1 [Thu, 04 Jan 2018 14:38:53 +0100] Ondřej Nový <onovy@debian.org>: * Team upload. <http://piuparts.knut.univention.de/5.0-7/#6908327987976077350>
OK: bug OK: yaml OK: announce_errata OK: patch OK: piuparts [5.0-7] 0c436db514 Bug #57272: python-idna 2.6-1+deb10u1 doc/errata/staging/python-idna.yaml | 6 +----- 1 file changed, 1 insertion(+), 5 deletions(-) [5.0-7] 5dc6583135 Bug #57272: python-idna 2.6-1+deb10u1 doc/errata/staging/python-idna.yaml | 17 +++++++++++++++++ 1 file changed, 17 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.0x1046>