Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Fedora 39: FEDORA-2024-28892f7c8f moderate: python-django DoS Risk

fedora
Calendar Grey September 6, 2024
Dist Fedora Esm H88
Django 4.2 security notice for Fedora 39 highlights possible DoS vulnerabilities linked to urlize and urlizetrunc when processing oversized inputs.
urlize and urlizetrunc were subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.

Summary

Django is a high-level Python Web framework that encourages rapid

development and a clean, pragmatic design. It focuses on automating as

much as possible and adhering to the DRY (Don't Repeat Yourself)

principle.

Update Information:

urlize and urlizetrunc were subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.

Change Log

* Wed Sep 4 2024 Michel Lind - 4.2.16-1 - Update to version 4.2.16 - Fixes: CVE-2024-45230, RHBZ#2309747 * Fri Jul 19 2024 Fedora Release Engineering - 4.2.14-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild

References


[ 1 ] Bug #2309747 - CVE-2024-45230: Potential denial-of-service vulnerability in django.utils.html.urlize() https://bugzilla.redhat.com/show_bug.cgi?id=2309747

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-28892f7c8f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Name: python-django4.2
Product: Fedora 39
Version: 4.2.16
Release: 1.fc39
Summary: A high-level Python Web framework

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here