Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

Ubuntu: USN-2671-1 Moderate: Python-Django Denial Of Service

Ubuntu Large Esm H500
Several security issues were fixed in Django.
=========================================================================Ubuntu Security Notice USN-2671-1
July 09, 2015

python-django vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.04
- Ubuntu 14.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in Django.

Software Description:
- python-django: High-level Python web development framework

Details:

Eric Peterson and Lin Hua Cheng discovered that Django incorrectly handled
session records. A remote attacker could use this issue to cause a denial
of service. (CVE-2015-5143)

Sjoerd Job Postmus discovered that DJango incorrectly handled newline
characters when performing validation. A remote attacker could use this
issue to perform header injection attacks. (CVE-2015-5144)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.04:
  python-django                   1.7.6-1ubuntu2.1
  python3-django                  1.7.6-1ubuntu2.1

Ubuntu 14.10:
  python-django                   1.6.6-1ubuntu2.3
  python3-django                  1.6.6-1ubuntu2.3

Ubuntu 14.04 LTS:
  python-django                   1.6.1-2ubuntu0.9

Ubuntu 12.04 LTS:
  python-django                   1.3.1-4ubuntu1.17

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2671-1
  CVE-2015-5143, CVE-2015-5144

Package Information:
  https://launchpad.net/ubuntu/+source/python-django/1.7.6-1ubuntu2.1
  https://launchpad.net/ubuntu/+source/python-django/1.6.6-1ubuntu2.3
  https://launchpad.net/ubuntu/+source/python-django/1.6.1-2ubuntu0.9
  https://launchpad.net/ubuntu/+source/python-django/1.3.1-4ubuntu1.17


Ubuntu: USN-2671-1 Moderate: Python-Django Denial Of Service

ubuntu
Calendar Grey July 9, 2015
Dist Ubuntu Esm H88
Debian Security Announcement DSA-4821-1 resolves issues in python-flask, tackling data exposure and command injection threats.
Several security issues were fixed in Django.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: python-django 1.7.6-1ubuntu2.1 python3-django 1.7.6-1ubuntu2.1 Ubuntu 14.10: python-django 1.6.6-1ubuntu2.3 python3-django 1.6.6-1ubuntu2.3 Ubuntu 14.04 LTS: python-django 1.6.1-2ubuntu0.9 Ubuntu 12.04 LTS: python-django 1.3.1-4ubuntu1.17 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2671-1

CVE-2015-5143, CVE-2015-5144

Severity
important
Lowest
Low
Medium
High
Critical

July 09, 2015

Package Information

https://launchpad.net/ubuntu/+source/python-django/1.7.6-1ubuntu2.1 https://launchpad.net/ubuntu/+source/python-django/1.6.6-1ubuntu2.3 https://launchpad.net/ubuntu/+source/python-django/1.6.1-2ubuntu0.9 https://launchpad.net/ubuntu/+source/python-django/1.3.1-4ubuntu1.17

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here