Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

openSUSE: 2024:0251-1 Important: Python-Django Denial of Service Threats

opensuse
Calendar Grey August 18, 2024
Dist Opensuse Esm H88
openSUSE Security Patch for python-Django addresses severe concerns, encompassing potential denial-of-service flaws.
An update that fixes 5 vulnerabilities is now available

Description

This update for python-Django fixes the following issues:

- CVE-2023-23969: Potential denial-of-service via Accept-Language headers

(boo#1207565)

- CVE-2024-38875: Potential denial-of-service attack via certain inputs

with a very large number of brackets (boo#1227590)

- CVE-2024-39329: Username enumeration through timing difference for users

with unusable passwords (boo#1227593)

- CVE-2024-39330: Potential directory traversal in

django.core.files.storage.Storage.save() (boo#1227594)

- CVE-2024-39614: Potential denial-of-service through

django.utils.translation.get_supported_language-variant() (boo#1227595)

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP5:

zypper in -t patch openSUSE-2024-251=1

Package List

References

https://www.suse.com/security/cve/CVE-2023-23969.html

https://www.suse.com/security/cve/CVE-2024-38875.html

https://www.suse.com/security/cve/CVE-2024-39329.html

https://www.suse.com/security/cve/CVE-2024-39330.html

https://www.suse.com/security/cve/CVE-2024-39614.html

https://bugzilla.suse.com/1207565

https://bugzilla.suse.com/1227590

https://bugzilla.suse.com/1227593

https://bugzilla.suse.com/1227594

https://bugzilla.suse.com/1227595

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2024:0251-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP5 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here