CVE-2024-3651

A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's handling of crafted input strings, which can lead to quadratic complexity and consequently, a denial of service condition. This vulnerability is triggered by a crafted input that causes the `idna.encode()` function to process the input with considerable computational load, significantly increasing the processing time in a quadratic manner relative to the input size.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kjd:internationalized_domain_names_in_applications:3.6:*:*:*:*:*:*:*

History

21 Nov 2024, 09:30

Type Values Removed Values Added
References () https://github.com/kjd/idna/commit/1d365e17e10d72d0b7876316fc7b9ca0eebdd38d - Patch () https://github.com/kjd/idna/commit/1d365e17e10d72d0b7876316fc7b9ca0eebdd38d - Patch
References () https://huntr.com/bounties/93d78d07-d791-4b39-a845-cbfabc44aadb - Exploit, Patch () https://huntr.com/bounties/93d78d07-d791-4b39-a845-cbfabc44aadb - Exploit, Patch

11 Jul 2024, 14:58

Type Values Removed Values Added
First Time Kjd
Kjd internationalized Domain Names In Applications
CPE cpe:2.3:a:kjd:internationalized_domain_names_in_applications:3.6:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : 6.2
v2 : unknown
v3 : 7.5
References () https://github.com/kjd/idna/commit/1d365e17e10d72d0b7876316fc7b9ca0eebdd38d - () https://github.com/kjd/idna/commit/1d365e17e10d72d0b7876316fc7b9ca0eebdd38d - Patch
References () https://huntr.com/bounties/93d78d07-d791-4b39-a845-cbfabc44aadb - () https://huntr.com/bounties/93d78d07-d791-4b39-a845-cbfabc44aadb - Exploit, Patch

08 Jul 2024, 15:49

Type Values Removed Values Added
Summary
  • (es) Se identificó una vulnerabilidad en la librería kjd/idna, específicamente dentro de la función `idna.encode()`, afectando a la versión 3.6. El problema surge del manejo por parte de la función de cadenas de entrada manipuladas, lo que puede generar complejidad cuadrática y, en consecuencia, una condición de denegación de servicio. Esta vulnerabilidad se activa por una entrada manipulada que hace que la función `idna.encode()` procese la entrada con una carga computacional considerable, aumentando significativamente el tiempo de procesamiento de manera cuadrática en relación con el tamaño de la entrada.

07 Jul 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-07 18:15

Updated : 2024-11-21 09:30


NVD link : CVE-2024-3651

Mitre link : CVE-2024-3651

CVE.ORG link : CVE-2024-3651


JSON object : View

Products Affected

kjd

  • internationalized_domain_names_in_applications
CWE
CWE-400

Uncontrolled Resource Consumption

NVD-CWE-noinfo