UbuntuUpdates.org

Package "python-idna"

Name: python-idna

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • Python IDNA2008 (RFC 5891) handling (Python 3)

Latest version: 3.6-2ubuntu0.2
Release: noble (24.04)
Level: security
Repository: main

Links



Other versions of "python-idna" in Noble

Repository Area Version
base main 3.6-2
updates main 3.6-2ubuntu0.2

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 3.6-2ubuntu0.2 2026-07-15 15:31:39 UTC

  python-idna (3.6-2ubuntu0.2) noble-security; urgency=medium

  * SECURITY UPDATE: DoS via specially crafted inputs to idna.encode()
    - debian/patches/CVE-2026-45409-1.patch: Reject oversized inputs up-front in
      idna/core.py, tests/test_idna.py.
    - debian/patches/CVE-2026-45409-2.patch: Use valid_string_length() for early
      oversized-input check in idna/core.py.
    - debian/patches/CVE-2026-45409-3.patch: Enforce early length limits in
      check_label in idna/core.py, tests/test_idna.py.
    - CVE-2026-45409

 -- Marc Deslauriers <email address hidden> Tue, 14 Jul 2026 13:20:53 -0400

Source diff to previous version
CVE-2026-45409 Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unico

Version: 3.6-2ubuntu0.1 2024-05-21 16:07:19 UTC

  python-idna (3.6-2ubuntu0.1) noble-security; urgency=medium

  * SECURITY UPDATE: resource exhaustion
    - debian/patches/CVE-2024-3651.patch: checks input before processing
    - CVE-2024-3651

 -- Jorge Sancho Larraz <email address hidden> Fri, 10 May 2024 10:55:01 +0200

CVE-2024-3651 potential DoS via resource consumption via specially crafted inputs to idna.encode()



About   -   Send Feedback to @ubuntu_updates