Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

SUSE Enterprise Storage 5: Moderate Python-Django Security Update Released

suse
Calendar Grey June 27, 2018
Dist Suse Esm H88
The latest update for Django addresses several critical security vulnerabilities. It is advised to follow the suggested installation methods to ensure your application remains secure.
An update that fixes three vulnerabilities is now available

Summary

This update for python-Django fixes the following security issues: - CVE-2016-2512: The utils.http.is_safe_url function allowed remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or possibly conduct cross-site scripting (XSS) attacks via a URL containing basic authentication (bsc#967999). - CVE-2018-7536: The django.utils.html.urlize() function was extremely slow to evaluate certain inputs due to catastrophic backtracking vulnerabilities (bsc#1083304). - CVE-2018-7537: If django.utils.text.Truncator's chars() and words() methods were passed the html=True argument, they were extremely slow to evaluate certain inputs due to a catastrophic backtracking vulnerability in a regular expression (bsc#1083305). Patch Instructions:

References

#1083304 #1083305 #967999

Cross- CVE-2016-2512 CVE-2018-7536 CVE-2018-7537

Affected Products:

SUSE Enterprise Storage 5

https://www.suse.com/security/cve/CVE-2016-2512.html

https://www.suse.com/security/cve/CVE-2018-7536.html

https://www.suse.com/security/cve/CVE-2018-7537.html

https://bugzilla.suse.com/1083304

https://bugzilla.suse.com/1083305

https://bugzilla.suse.com/967999

Announcement ID: SUSE-SU-2018:1830-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here