|
|
| |
|
| |
django: denial of service
| Package(s): | django |
CVE #(s): | |
| Created: | October 16, 2009 |
Updated: | October 21, 2009 |
| Description: |
From the Django
project advisory: Django's forms library includes field types which perform regular-expression-based validation of email addresses and URLs. Certain addresses/URLs could trigger a pathological performance case in these regular expression, resulting in the server process/thread becoming unresponsive, and consuming excessive CPU over an extended period of time. If deliberately triggered, this could result in an effective denial-of-service attack. |
| Alerts: |
|
( Log in to post comments)
|
|
|