LWN.net Logo

python-django: information disclosure

Package(s):python-django CVE #(s):CVE-2012-4520
Created:October 30, 2012 Updated:March 8, 2013
Description: From the Mageia advisory:

The Host header parsing in Django 1.3 and Django 1.4 -- specifically, django.http.HttpRequest.get_host() -- was incorrectly handling username/password information in the header. Using this, an attacker can cause parts of Django -- particularly the password-reset mechanism -- to generate and display arbitrary URLs to users.

Alerts:
Mageia MGASA-2012-0315 2012-10-29
Fedora FEDORA-2012-16417 2012-10-30
Fedora FEDORA-2012-16440 2012-10-31
Ubuntu USN-1632-1 2012-11-15
Ubuntu USN-1632-2 2012-11-20
Mandriva MDVSA-2012:181 2012-12-19
Debian DSA-2634-1 2013-02-27
Ubuntu USN-1757-1 2013-03-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds