LWN.net Logo

django: denial of service

Package(s):django CVE #(s):
Created:October 16, 2009 Updated:October 21, 2009
Description: From the Django project advisory: Django's forms library includes field types which perform regular-expression-based validation of email addresses and URLs. Certain addresses/URLs could trigger a pathological performance case in these regular expression, resulting in the server process/thread becoming unresponsive, and consuming excessive CPU over an extended period of time. If deliberately triggered, this could result in an effective denial-of-service attack.
Alerts:
Fedora FEDORA-2009-10390 2009-10-14
Fedora FEDORA-2009-10432 2009-10-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds