Home page logo

bugtraq logo Bugtraq mailing list archives

[SECURITY] [DSA 2634-1] python-django security update
From: Nico Golde <nion () debian org>
Date: Wed, 27 Feb 2013 00:58:40 +0100

Hash: SHA1

- -------------------------------------------------------------------------
Debian Security Advisory DSA-2634-1                   security () debian org
http://www.debian.org/security/                                Nico Golde
February 27, 2013                      http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : python-django
Vulnerability  : several
Problem type   : remote
Debian-specific: no
CVE ID         : CVE-2012-4520 CVE-2013-0305 CVE-2013-0306 CVE-2013-1665
Debian Bug     : 701186 696535 691145

Several vulnerabilities have been discovered in python-django, a high-level
python web development framework.  The Common Vulnerabilities and
Exposures project identifies the following problems:


    James Kettle discovered that django did not properly filter the HTTP
    Host header when processing certain requests. An attacker could exploit
    this to generate and cause parts of django, particularly the
    password-reset mechanism, to display arbitrary URLs to users.


    Orange Tsai discovered that the bundled administrative interface
    of django could expose supposedly-hidden information via its history


    Mozilla discovered that an attacker can abuse django's tracking of
    the number of forms in a formset to cause a denial-of-service attack
    due to extreme memory consumption.


    Michael Koziarski discovered that django's XML deserialization is
    vulnerable to entity-expansion and external-entity/DTD attacks.

For the stable distribution (squeeze), these problems have been fixed in
version 1.2.3-3+squeeze5.

For the testing distribution (wheezy), these problems will be fixed soon.

For the unstable distribution (sid), these problems have been fixed in
version 1.4.4-1.

We recommend that you upgrade your python-django packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/

Mailing list: debian-security-announce () lists debian org
Version: GnuPG v1.4.12 (GNU/Linux)


  By Date           By Thread  

Current thread:
  • [SECURITY] [DSA 2634-1] python-django security update Nico Golde (Feb 27)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]