Amazon Linux 2 Security Advisory: ALAS2PYTHON3.8-2024-015
Advisory Released Date: 2024-11-13
Advisory Updated Date: 2024-11-15
Severity:
Medium
Issue Overview:
python-idna: potential DoS via resource consumption via specially crafted inputs to idna.encode() (CVE-2024-3651)
Affected Packages:
python38-pip
Note:
This advisory is applicable to Amazon Linux 2 - Python3.8 Extra. Visit this page to learn more about Amazon Linux 2 (AL2) Extras and this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update python38-pip to update your system.
New Packages:
noarch:
python38-pip-21.0.1-4.amzn2.0.3.noarch
src:
python38-pip-21.0.1-4.amzn2.0.3.src