Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Ubuntu 11.10 USN-1297-1: Python-Django Denial of Service Issues

ubuntu
Calendar Grey December 9, 2011
Scroller Ubuntu
Flaws in Django on Ubuntu systems may result in application failures and the leakage of confidential information, jeopardizing overall security.
Applications using Django could be made to crash or expose sensitive information.

Summary

Applications using Django could be made to crash or expose sensitive

information.

Software Description:

- python-django: High-level Python web development framework

Details:

Pall McMillan discovered that Django used the root namespace when storing

cached session data. A remote attacker could exploit this to modify

sessions. (CVE-2011-4136)

Paul McMillan discovered that Django would not timeout on arbitrary URLs

when the application used URLFields. This could be exploited by a remote

attacker to cause a denial of service via resource exhaustion.

(CVE-2011-4137)

Paul McMillan discovered that while Django would check the validity of a

URL via a HEAD request, it would instead use a GET request for the target

of a redirect. This could potentially be used to trigger arbitrary GET

requests via a crafted Location header. (CVE-2011-4138)

It was discovered that Django would sometimes use a request's HTTP Host

header to construct a full URL. A remote attacker cou...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
  python-django                   1.3-2ubuntu1.1

Ubuntu 11.04:
  python-django                   1.2.5-1ubuntu1.1

Ubuntu 10.10:
  python-django                   1.2.3-1ubuntu0.2.10.10.3

Ubuntu 10.04 LTS:
  python-django                   1.1.1-2ubuntu1.4

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1297-1

CVE-2011-4136, CVE-2011-4137, CVE-2011-4138, CVE-2011-4139

Severity
important
Lowest
Low
Medium
High
Critical

December 09, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.