Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Django could be made to expose sensitive information over the network.
Software Description:
- python-django: High-level Python web development framework
Details:
Ryan Butterfield discovered that Django incorrectly handled the date
template filter. A remote attacker could possibly use this issue to obtain
secrets from application settings.
The problem can be corrected by updating your system to the following package versions: Ubuntu 15.10: python-django 1.7.9-1ubuntu5.1 python3-django 1.7.9-1ubuntu5.1 Ubuntu 15.04: python-django 1.7.6-1ubuntu2.3 python3-django 1.7.6-1ubuntu2.3 Ubuntu 14.04 LTS: python-django 1.6.1-2ubuntu0.11 Ubuntu 12.04 LTS: python-django 1.3.1-4ubuntu1.19 In general, a standard system update will make all the necessary changes.
CVE-2015-8213
Get the latest Linux and open source security news straight to your inbox.