LWN.net Logo

django: multiple vulnerabilities

Package(s):python-django CVE #(s):CVE-2013-0305 CVE-2013-0306
Created:February 27, 2013 Updated:March 22, 2013
Description: From the Debian advisory:

CVE-2013-0305: Orange Tsai discovered that the bundled administrative interface of django could expose supposedly-hidden information via its history log.

CVE-2013-0306: Mozilla discovered that an attacker can abuse django's tracking of the number of forms in a formset to cause a denial-of-service attack due to extreme memory consumption.

Alerts:
Debian DSA-2634-1 2013-02-27
Mageia MGASA-2013-0076 2013-03-01
Ubuntu USN-1757-1 2013-03-07
Fedora FEDORA-2013-2843 2013-03-12
Fedora FEDORA-2013-2874 2013-03-12
Red Hat RHSA-2013:0670-01 2013-03-21

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds