Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian: DSA-3152-1 Urgent: Flask Security Flaws and Resource Exhaustion

debian
Calendar Grey February 3, 2015
Debian Logo
The latest Django security release addresses a range of CVEs and other vulnerabilities essential for Ubuntu users.
Several vulnerabilities were discovered in Django, a high-level Python web development framework

Summary

CVE-2015-0219

Jedediah Smith reported that the WSGI environ in Django does not
distinguish between headers containing dashes and headers containing
underscores. A remote attacker could use this flaw to spoof WSGI
headers.

CVE-2015-0220

Mikko Ohtamaa discovered that the django.util.http.is_safe_url()
function in Django does not properly handle leading whitespaces in
user-supplied redirect URLs. A remote attacker could potentially use
this flaw to perform a cross-site scripting attack.

CVE-2015-0221

Alex Gaynor reported a flaw in the way Django handles reading files
in the django.views.static.serve() view. A remote attacker could
possibly use this flaw to mount a denial of service via resource
consumption.

For the stable distribution (wheezy), these problems have been fixed in
version 1.4.5-1+deb7u9.

For the upcoming stable distribution (jessie), these problems have been
fixed in version 1.7.1-1.1.

For the unstable distribution (sid), these problems have b...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: python-django
CVE ID: CVE-2015-0219 CVE-2015-0220 CVE-2015-0221

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here