Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 943630 (CVE-2024-11168) - <dev-lang/python-{3.10.15_p2,3.9.20_p2,3.8.20_p3}, <dev-lang/pypy-3.10.7.3.17_p2:3.10, dev-python/pypy3_10: Improper validation of IPv6 and IPvFuture addresses
Summary: <dev-lang/python-{3.10.15_p2,3.9.20_p2,3.8.20_p3}, <dev-lang/pypy-3.10.7.3.17...
Status: CONFIRMED
Alias: CVE-2024-11168
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL:
Whiteboard: A4 [glsa?]
Keywords:
Depends on: 943631 943632 943633 943634
Blocks:
  Show dependency tree
 
Reported: 2024-11-16 14:29 UTC by Michał Górny
Modified: 2025-01-05 08:14 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2024-11-16 14:29:33 UTC
There is a MEDIUM severity vulnerability affecting CPython.

The urllib.parse.urlsplit() and urlparse() functions improperly validated
bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This
behavior was not conformant to RFC 3986 and potentially enabled SSRF if a
URL is processed by more than one URL parser.

----

Apparently it was fixed in 3.11.4, but not considered a vulnerability then, and never backported to earlier versions.
Comment 1 Hans de Graaff gentoo-dev Security 2025-01-05 08:14:06 UTC
My vote would be noglsa.