Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Ubuntu Security Notice USN-3254-1: Addressing XSS Vulnerabilities in Django

Ubuntu Large Esm H500
Several security issues were fixed in Django.
=========================================================================Ubuntu Security Notice USN-3254-1
April 04, 2017

python-django vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.10
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in Django.

Software Description:
- python-django: High-level Python web development framework

Details:

It was discovered that Django incorrectly handled numeric redirect URLs. A
remote attacker could possibly use this issue to perform XSS attacks, and
to use a Django server as an open redirect. (CVE-2017-7233)

Phithon Gong discovered that Django incorrectly handled certain URLs when
the jango.views.static.serve() view is being used. A remote attacker could
possibly use a Django server as an open redirect. (CVE-2017-7234)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.10:
  python-django                   1.8.7-1ubuntu8.2
  python3-django                  1.8.7-1ubuntu8.2

Ubuntu 16.04 LTS:
  python-django                   1.8.7-1ubuntu5.5
  python3-django                  1.8.7-1ubuntu5.5

Ubuntu 14.04 LTS:
  python-django                   1.6.11-0ubuntu1.1

Ubuntu 12.04 LTS:
  python-django                   1.3.1-4ubuntu1.23

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-3254-1
  CVE-2017-7233, CVE-2017-7234

Package Information:
  https://launchpad.net/ubuntu/+source/python-django/1.8.7-1ubuntu8.2
  https://launchpad.net/ubuntu/+source/python-django/1.8.7-1ubuntu5.5
  https://launchpad.net/ubuntu/+source/python-django/1.6.11-0ubuntu1.1
  https://launchpad.net/ubuntu/+source/python-django/1.3.1-4ubuntu1.23


Ubuntu Security Notice USN-3254-1: Addressing XSS Vulnerabilities in Django

ubuntu
Calendar Grey April 4, 2017
Dist Ubuntu Esm H88
Security vulnerabilities in Django addressed in recent Ubuntu updates. Detailed update procedures provided for the impacted versions.
Several security issues were fixed in Django.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.10: python-django 1.8.7-1ubuntu8.2 python3-django 1.8.7-1ubuntu8.2 Ubuntu 16.04 LTS: python-django 1.8.7-1ubuntu5.5 python3-django 1.8.7-1ubuntu5.5 Ubuntu 14.04 LTS: python-django 1.6.11-0ubuntu1.1 Ubuntu 12.04 LTS: python-django 1.3.1-4ubuntu1.23 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-3254-1

CVE-2017-7233, CVE-2017-7234

Severity
important
Lowest
Low
Medium
High
Critical

April 04, 2017

Package Information

https://launchpad.net/ubuntu/+source/python-django/1.8.7-1ubuntu8.2 https://launchpad.net/ubuntu/+source/python-django/1.8.7-1ubuntu5.5 https://launchpad.net/ubuntu/+source/python-django/1.6.11-0ubuntu1.1 https://launchpad.net/ubuntu/+source/python-django/1.3.1-4ubuntu1.23

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here