An auto-block can occur for an untrusted X-Forwarded-For header in MediaWiki, a website engine for collaborative work. X-Forwarded-For is not necessarily trustworthy and can specify multiple IP . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3540-1
Several security issues were fixed in Django.. =========================================================================Ubuntu Security Notice USN-2469-1 January 13, 2015 python-django vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS - Ubuntu 10.04 LTS Summary: Several security issues were fixed in Django. Software Description: - python-django: High-level Python web development framework Details: Jedediah Smith discovered that Django incorrectly handled underscores in WSGI headers. A remote attacker could possibly use this issue to spoof headers in certain environments. (CVE-2015-0219) Mikko Ohtamaa discovered that Django incorrectly handled user-supplied redirect URLs. A remote attacker could possibly use this issue to perform a cross-site scripting attack. (CVE-2015-0220) Alex Gaynor discovered that Django incorrectly handled reading files in django.views.static.serve(). A remote attacker could possibly use this issue to cause Django to consume resources, resulting in a denial of service. (CVE-2015-0221) Keryn Knight discovered that Django incorrectly handled forms with ModelMultipleChoiceField. A remote attacker could possibly use this issue to cause a large number of SQL queries, resulting in a database denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 14.10. (CVE-2015-0222) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.10: python-django 1.6.6-1ubuntu2.1 python3-django 1.6.6-1ubuntu2.1 Ubuntu 14.04 LTS: python-django 1.6.1-2ubuntu0.6 Ubuntu 12.04 LTS: python-django 1.3.1-4ubuntu1.13 Ubuntu 10.04 LTS: python-django 1.1.1-2ubuntu1.14 In general, a standard system update will makeall the necessary changes. References: https://ubuntu.com/security/notices/USN-2469-1 CVE-2015-0219, CVE-2015-0220, CVE-2015-0221, CVE-2015-0222 Package Information: https://launchpad.net/ubuntu/+source/python-django/1.6.6-1ubuntu2.1 https://launchpad.net/ubuntu/+source/python-django/1.6.1-2ubuntu0.6 https://launchpad.net/ubuntu/+source/python-django/1.3.1-4ubuntu1.13 https://launchpad.net/ubuntu/+source/python-django/1.1.1-2ubuntu1.14 . Key security vulnerabilities in Django have been fixed across various Ubuntu distributions. Refer to the official documentation for updates and detailed risk assessments. Django Security Update, Python Django Fix, Ubuntu Security Advisory. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.