Bug 2103107 (CVE-2022-33124) - CVE-2022-33124 python-aiohttp: invalid IPv6 URL which can lead to a Denial of Service with exception raised
Summary: CVE-2022-33124 python-aiohttp: invalid IPv6 URL which can lead to a Denial of...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2022-33124
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2103108
Blocks: 2103109
TreeView+ depends on / blocked
 
Reported: 2022-07-01 13:07 UTC by Marian Rehak
Modified: 2023-04-04 12:21 UTC (History)
41 users (show)

Fixed In Version:
Doc Type: No Doc Update
Doc Text:
Clone Of:
Environment:
Last Closed: 2022-07-20 11:39:27 UTC
Embargoed:


Attachments (Terms of Use)

Description Marian Rehak 2022-07-01 13:07:17 UTC
An invalid IPv6 URL outcome, which can lead to a Denial of Service (DoS).

Reference:

https://github.com/aio-libs/aiohttp/issues/6772

Comment 1 Marian Rehak 2022-07-01 13:07:40 UTC
Created python-aiohttp tracking bugs for this issue:

Affects: fedora-all [bug 2103108]


Note You need to log in before you can comment on or make changes to this bug.