LWN.net Logo

python-django: denial of service

Package(s):python-django CVE #(s):CVE-2009-3695
Created:October 13, 2009 Updated:December 9, 2009
Description: From the Mandriva advisory: Algorithmic complexity vulnerability in the forms library in Django 1.0 before 1.0.4 and 1.1 before 1.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a crafted (1) EmailField (email address) or (2) URLField (URL) that triggers a large amount of backtracking in a regular expression.
Alerts:
Mandriva MDVSA-2009:276-1 2009-12-08
Debian DSA-1905-1 2009-10-10
Mandriva MDVSA-2009:276 2009-10-13

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds