Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Ubuntu 16.04 ESM & 14.04 ESM: USN-5269-2 Moderate: Django Security Fixes

Ubuntu Large Esm H500
Several security issues were fixed in Django.
=========================================================================Ubuntu Security Notice USN-5269-2
February 07, 2022

python-django vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM
- Ubuntu 14.04 ESM

Summary:

Several security issues were fixed in Django.

Software Description:
- python-django: High-level Python web development framework

Details:

USN-5269-1 fixed several vulnerabilities in Django. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.

Original advisory details:

 Keryn Knight discovered that Django incorrectly handled certain template
 tags. A remote attacker could possibly use this issue to perform a
 cross-site scripting attack. (CVE-2022-22818)

 Alan Ryan discovered that Django incorrectly handled file uploads. A remote
 attacker could possibly use this issue to cause Django to hang, resulting
 in a denial of service. (CVE-2022-23833)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
  python-django                   1.8.7-1ubuntu5.15+esm4
  python3-django                  1.8.7-1ubuntu5.15+esm4

Ubuntu 14.04 ESM:
  python-django                   1.6.11-0ubuntu1.3+esm4

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-5269-2
  https://ubuntu.com/security/notices/USN-5269-1
  CVE-2022-22818, CVE-2022-23833

Ubuntu 16.04 ESM & 14.04 ESM: USN-5269-2 Moderate: Django Security Fixes

ubuntu
Calendar Grey February 7, 2022
Dist Ubuntu Esm H88
Enhance the security of your Django web apps on Ubuntu 14.04 and 16.04 ESM by applying these essential fixes to mitigate vulnerabilities
Several security issues were fixed in Django.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: python-django 1.8.7-1ubuntu5.15+esm4 python3-django 1.8.7-1ubuntu5.15+esm4 Ubuntu 14.04 ESM: python-django 1.6.11-0ubuntu1.3+esm4 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5269-2

https://ubuntu.com/security/notices/USN-5269-1

CVE-2022-22818, CVE-2022-23833

February 07, 2022

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here