Bug 2369303 (CVE-2024-12224)
| Summary: | CVE-2024-12224 idna: idna accepts Punycode labels that do not produce any non-ASCII when decoded | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | anthomas, dbosanac, dhanak, drosa, dsimansk, ehelms, ggainey, gkamathe, gotiwari, haoli, hkataria, jajackso, jcammara, jhorak, jkoehler, jmitchel, jneedle, jreimann, juwatts, kegrant, kingland, koliveir, kshier, kverlaen, lball, lphiri, mabashia, matzew, mdessi, mhulan, mnovotny, mrizzi, mvyas, ngough, nkathole, nmoumoul, osousa, pbraun, pcattana, pcreech, rchan, sausingh, shvarugh, simaishi, smallamp, smcdonal, stcannon, teagle, tfister, thavo, tpopela, veshanka, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in idna crate. This vulnerability allows hostname spoofing and potential privilege escalation via specially crafted Punycode labels that render as ASCII or empty labels, leading to incorrect equality comparisons during hostname validation.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2370556, 2370558, 2370562, 2370569, 2370572, 2370576, 2370581, 2370582, 2370585, 2370588, 2370590, 2370592, 2370595, 2370596, 2370603, 2370557, 2370559, 2370560, 2370561, 2370563, 2370564, 2370565, 2370566, 2370567, 2370568, 2370570, 2370571, 2370573, 2370574, 2370575, 2370577, 2370578, 2370579, 2370580, 2370583, 2370584, 2370586, 2370587, 2370589, 2370591, 2370593, 2370594, 2370597, 2370598, 2370599, 2370600, 2370601, 2370602 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2025-05-30 02:01:11 UTC
|