ALAS-2024-764


Amazon Linux 2023 Security Advisory: ALAS-2024-764
Advisory Release Date: 2024-11-13 12:28 Pacific
Advisory Updated Date: 2024-11-14 11:00 Pacific
Severity: Medium

Issue Overview:

python-idna: potential DoS via resource consumption via specially crafted inputs to idna.encode() (CVE-2024-3651)


Affected Packages:

python-pip


Issue Correction:
Run dnf update python-pip --releasever 2023.6.20241111 to update your system.

New Packages:
noarch:
    python3-pip-wheel-21.3.1-2.amzn2023.0.9.noarch
    python3-pip-21.3.1-2.amzn2023.0.9.noarch

src:
    python-pip-21.3.1-2.amzn2023.0.9.src