Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: kodiPackages.idna

Found 1 matching suggestions

View:
Compact
Detailed
Untriaged
created 6 months ago
idna accepts Punycode labels that do not produce any non-ASCII when decoded

Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.

Affected products

idna
  • <1.0.0

Matching in nixpkgs

pkgs.echidna

Ethereum smart contract fuzzer

  • nixos-unstable -

pkgs.unicode-idna

Unicode IDNA compatible processing data

  • nixos-unstable -

Package maintainers