Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Ubuntu 15.10 USN-2915-1 High: Django Remote Attack Issues

ubuntu
Calendar Grey March 1, 2016
Scroller Ubuntu
Update your Django framework and Ubuntu packages to strengthen your security posture. This guide outlines the necessary steps and assesses their impacts on security
Several security issues were fixed in Django.

Summary

Several security issues were fixed in Django.

Software Description:

- python-django: High-level Python web development framework

Details:

Mark Striemer discovered that Django incorrectly handled user-supplied

redirect URLs containing basic authentication credentials. A remote

attacker could possibly use this issue to perform a cross-site scripting

attack or a malicious redirect. (CVE-2016-2512)

Sjoerd Job Postmus discovered that Django incorrectly handled timing when

doing password hashing operations. A remote attacker could possibly use

this issue to perform user enumeration. (CVE-2016-2513)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
  python-django                   1.7.9-1ubuntu5.2
  python3-django                  1.7.9-1ubuntu5.2

Ubuntu 14.04 LTS:
  python-django                   1.6.1-2ubuntu0.12

Ubuntu 12.04 LTS:
  python-django                   1.3.1-4ubuntu1.20

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2915-1

CVE-2016-2512, CVE-2016-2513

March 01, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.