LWN.net Logo

python-django: directory traversal

Package(s):python-django CVE #(s):CVE-2009-2659
Created:October 13, 2009 Updated:December 9, 2009
Description: From the Mandriva update: The Admin media handler in core/servers/basehttp.py in Django 1.0 and 0.96 does not properly map URL requests to expected static media files, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a crafted URL.
Alerts:
Mandriva MDVSA-2009:276-1 2009-12-08
Mandriva MDVSA-2009:276 2009-10-13
Mandriva MDVSA-2009:275 2009-10-13

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds