ALAS-2024-762


Amazon Linux 2023 Security Advisory: ALAS-2024-762
Advisory Release Date: 2024-11-13 12:28 Pacific
Advisory Updated Date: 2024-11-14 11:00 Pacific
Severity: Medium

Issue Overview:

python-idna: potential DoS via resource consumption via specially crafted inputs to idna.encode() (CVE-2024-3651)


Affected Packages:

python3.11-pip


Issue Correction:
Run dnf update python3.11-pip --releasever 2023.6.20241111 to update your system.

New Packages:
noarch:
    python3.11-pip-wheel-22.3.1-2.amzn2023.0.4.noarch
    python3.11-pip-22.3.1-2.amzn2023.0.4.noarch

src:
    python3.11-pip-22.3.1-2.amzn2023.0.4.src