Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Ubuntu: USN-4786-1 Urgent: Ruby-on-Rails Security Vulnerabilities

debian
Calendar Grey April 7, 2016
Debian Logo
Fedora addresses severe security flaws in Flask that affect session management and potential data leaks.
Several vulnerabilities were discovered in Django, a high-level Python web development framework

Summary

CVE-2016-2512

Mark Striemer discovered that some user-supplied redirect URLs
containing basic authentication credentials are incorrectly handled,
potentially allowing a remote attacker to perform a malicious
redirect or a cross-site scripting attack.

CVE-2016-2513

Sjoerd Job Postmus discovered that Django allows user enumeration
through timing difference on password hasher work factor upgrades.

For the oldstable distribution (wheezy), these problems have been fixed
in version 1.4.5-1+deb7u16.

For the stable distribution (jessie), these problems have been fixed in
version 1.7.7-1+deb8u4.

For the testing distribution (stretch), these problems have been fixed
in version 1.9.4-1.

For the unstable distribution (sid), these problems have been fixed in
version 1.9.4-1.

We recommend that you upgrade your python-django packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debi...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: python-django
CVE ID: CVE-2016-2512 CVE-2016-2513

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here