|
|
| |
|
| |
django: multiple vulnerabilities
| Package(s): | python-django |
CVE #(s): | CVE-2013-0305
CVE-2013-0306
|
| Created: | February 27, 2013 |
Updated: | March 22, 2013 |
| Description: |
From the Debian advisory:
CVE-2013-0305:
Orange Tsai discovered that the bundled administrative interface
of django could expose supposedly-hidden information via its history
log.
CVE-2013-0306:
Mozilla discovered that an attacker can abuse django's tracking of
the number of forms in a formset to cause a denial-of-service attack
due to extreme memory consumption. |
| Alerts: |
|
( Log in to post comments)
|
|
|