Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Debian 11: DLA-4010-1 python-django moderate: email injection fix

debian lts
Calendar Grey January 11, 2025
Dist Debian Esm H88
Enhance your django installation to bolster email security following the resolution of CVE-2024-6923, alongside modifications to add new features.
The fix for CVE-2024-6923 in the python3.9 source package which was released as part of a suite of updates in DLA 3980-1 [0] introduced safer processing of input in the email modul...

Summary

This change inadvertedly broke sending emails when using lazy
translation strings in the python-django package, however, resulting
in the package no longer building from source.

As the previous behaviour of Python's "email" module can be enabled
by passing the strict=False flag, the python-django package now does
so — Django detects and/or encodes newlines in its handling of
outbound emails elsewhere.

For Debian 11 bullseye, this change has been made in version
2:2.2.28-1~deb11u4.

We recommend that you upgrade your python-django packages.

For the detailed security status of python-django please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/python-django

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

[0] https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html


Package: python-django
Version: 2:2.2.28-1~deb11u4
CVE ID: CVE-2024-6923

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here