Bug 33132 - python-idna new security issue CVE-2024-3651
Summary: python-idna new security issue CVE-2024-3651
Status: NEW
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2024-04-23 15:41 CEST by Nicolas Salguero
Modified: 2024-06-29 20:41 CEST (History)
4 users (show)

See Also:
Source RPM: python-idna-3.4-2.mga9.src.rpm
CVE: CVE-2024-3651
Status comment:


Attachments

Description Nicolas Salguero 2024-04-23 15:41:53 CEST
Fedora has issued an advisory on April 23:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QKQPAXBXFNOVCI2IKRUG56LWQVB6H64Y/

The issue is fixed in version 3.7.

Mageia 9 is also affected.
Nicolas Salguero 2024-04-23 15:42:18 CEST

Source RPM: (none) => python-idna-3.4-3.mga10.src.rpm
Status comment: (none) => Fixed upstream in 3.7
Whiteboard: (none) => MGA9TOO
CVE: (none) => CVE-2024-3651

Comment 1 Lewis Smith 2024-04-24 21:18:02 CEST
(On an M9 system, I can only see version 3.3 in Cauldron).

No one packager obvious for this RPM, so assigning to Python people.

Assignee: bugsquad => python

Comment 2 papoteur 2024-06-27 18:01:04 CEST
Cauldron updated to 3.7

CC: (none) => yvesbrungard
Whiteboard: MGA9TOO => (none)
Version: Cauldron => 9
Source RPM: python-idna-3.4-3.mga10.src.rpm => python-idna-3.4-2.mga9.src.rpm

Comment 3 papoteur 2024-06-28 08:34:26 CEST
Submitting:
RPMS:
python3-idna-3.7-1.mga9.noarch
SRPMS:
python-idna-3.7-1.mga9

Assignee: python => qa-bugs
Status comment: Fixed upstream in 3.7 => (none)

katnatek 2024-06-29 01:10:17 CEST

Keywords: (none) => advisory

Comment 4 Herman Viaene 2024-06-29 10:53:18 CEST
MGA9-64  Plasma Wayland on  HP-Pavillion.
No installation issues.
Looking for som testing
# urpmq --whatrequires python3-idna
python3-anyio
python3-cobaya
python3-email-validator
python3-hyperlink
python3-idna
python3-jsonschema+format
python3-jsonschema+format-nongpl
python3-nbxmpp
python3-requests
python3-requests
python3-requests
python3-rfc3986+idna2008
python3-trio
python3-trustme
python3-twisted+tls
python3-yarl
syslog-ng-python-modules
So seems deep in developers territory.
]# urpmq --whatrequires-recursive python3-idna

returns somethinh like 15 screenlenghts of packages....
Giving the OK on clean install and good behavior as we often do for developers stuff.

CC: (none) => herman.viaene
Whiteboard: (none) => MGA9-64-OK

Comment 5 Thomas Andrews 2024-06-29 20:41:10 CEST
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs


Note You need to log in before you can comment on or make changes to this bug.