Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Debian: DSA-2634-1 Critical: python-django Remote Attack Issues

debian
Calendar Grey February 27, 2013
Debian Logo
Multiple security flaws in the python-django package necessitate urgent updates for Debian users to maintain safety and functionality.
Several vulnerabilities have been discovered in python-django, a high-level python web development framework

Summary

Several vulnerabilities have been discovered in python-django, a high-level
python web development framework. The Common Vulnerabilities and
Exposures project identifies the following problems:


CVE-2012-4520

James Kettle discovered that django did not properly filter the HTTP
Host header when processing certain requests. An attacker could exploit
this to generate and cause parts of django, particularly the
password-reset mechanism, to display arbitrary URLs to users.

CVE-2013-0305

Orange Tsai discovered that the bundled administrative interface
of django could expose supposedly-hidden information via its history
log.

CVE-2013-0306

Mozilla discovered that an attacker can abuse django's tracking of
the number of forms in a formset to cause a denial-of-service attack
due to extreme memory consumption.

CVE-2013-1665

Michael Koziarski discovered that django's XML deserialization is
vulnerable to entity-expansion and external-entity/DTD attacks.

For the stabl...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: python-django
CVE ID: CVE-2012-4520 CVE-2013-0305 CVE-2013-0306 CVE-2013-1665

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here