Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Debian: DLA-2042-1 Moderate: Python-Django Account Hijack Issue

debian lts
Calendar Grey December 18, 2019
Dist Debian Esm H88
Upgrade to Python-django version 1.7.11-1+deb8u8 to address vulnerabilities related to account takeover. This update ensures enhanced security protocols.
It was discovered that there was a potential account hijack vulnerabilility in Django, the Python-based web development framework

Summary

To resolve this, two changes were made in Django:

* After retrieving a list of potentially-matching accounts from the
database, Django's password reset functionality now also checks
the email address for equivalence in Python, using the
recommended identifier-comparison process from Unicode Technical
Report 36, section 2.11.2(B)(2).

* When generating password-reset emails, Django now sends to the
email address retrieved from the database, rather than the email
address submitted in the password-reset request form.

For more information, please see:

https://www.djangoproject.com/weblog/2019/dec/18/security-releases/

For Debian 8 "Jessie", this issue has been fixed in python-django version
1.7.11-1+deb8u8.

We recommend that you upgrade your python-django packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Regards,

- --
,'`.

Read the Full Advisory


Package: python-django
Version: 1.7.11-1+deb8u8
CVE ID: CVE-2019-19844
Debian Bug: #946937

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here