Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian GNU/Linux Lenny: DSA-1905-1 Critical DoS in python-django

debian
Calendar Grey October 10, 2009
Debian Logo
Debian DSA-1905-2 fixes a security vulnerability in the python-django package related to improper handling of user input, resulting in potential denial of service.
The forms library of python-django, a high-level Python web development framework, is using a badly chosen regular expression when validating email addresses and URLs

Summary

The forms library of python-django, a high-level Python web development
framework, is using a badly chosen regular expression when validating
email addresses and URLs. An attacker can use this to perform denial
of service attacks (100% CPU consumption) due to bad backtracking
via a specially crafted email address or URL which is validated by the
django forms library.


python-django in the oldstable distribution (etch), is not affected by
this problem.

For the stable distribution (lenny), this problem has been fixed in
version 1.0.2-1+lenny2.

For the testing distribution (squeeze), this problem will be fixed soon.

For the unstable distribution (sid), this problem has been fixed in
version 1.1.1-1.


We recommend that you upgrade your python-django packages.

Upgrade instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: python-django
CVE ID: None yet

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here