Alerts This Week
Warning Icon 1 1,154
Alerts This Week
Warning Icon 1 1,154

Ubuntu 21.04 USN-4932-1 Moderate: Django File Overwrite Risk

ubuntu
Calendar Grey May 4, 2021
Dist Ubuntu Esm H88
Django security flaw enables file replacement in Ubuntu systems. Upgrade your python-django version to mitigate the issue.
Django could be made to overwrite files.

Summary

Django could be made to overwrite files.

Software Description:

- python-django: High-level Python web development framework

Details:

It was discovered that Django incorrectly handled certain

filenames. A remote attacker could possibly use this issue to create or

overwrite files in unexpected directories.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 21.04:
  python3-django                  2:2.2.20-1ubuntu0.1

Ubuntu 20.10:
  python3-django                  2:2.2.16-1ubuntu0.4

Ubuntu 20.04 LTS:
  python3-django                  2:2.2.12-1ubuntu0.6

Ubuntu 18.04 LTS:
  python-django                   1:1.11.11-1ubuntu1.13
  python3-django                  1:1.11.11-1ubuntu1.13

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4932-1

CVE-2021-31542

Severity
important
Lowest
Low
Medium
High
Critical

May 04, 2021

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here