|
|
Subscribe / Log in / New account

Debian alert DLA-4006-1 (python-django)

From:  Chris Lamb <lamby@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 4006-1] python-django security update
Date:  Tue, 31 Dec 2024 16:01:44 +0000
Message-ID:  <173565706647.377616.3498062011138837315@copycat>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4006-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Chris Lamb December 31, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : python-django Version : 2:2.2.28-1~deb11u3 CVE ID : CVE-2024-53907 It was discovered that there was a potential Denial of Service (DoS) vulnerability, in Django, a popular Python-based web development framework. The strip_tags() method and striptags template filter were subject to a potential denial-of-service attack via certain inputs containing large sequences of nested incomplete HTML entities. For Debian 11 bullseye, this problem has been fixed in version 2:2.2.28-1~deb11u3. We recommend that you upgrade your python-django packages. For the detailed security status of python-django please refer to its security tracker page at: https://security-tracker.debian.org/tracker/python-django Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmd0BmgACgkQHpU+J9Qx HlhLFhAAwcroO4+AxOc6RTndU6qJgzxwvCmBcT7g8bynBfFKvEQ/0Ybmk2Y6hM6q wU6493V1M/TjKEpzWuytsBo0lTMHqMuXvne/iTuNNNoru0GIvCO2NfkAQNvMtUiY FKpWFUMoOx6ezbuvr/wWl4T94vuzZYJhajXoyDffCb6iEOdO3lbbbG0fEuuqkQq1 0BYrgocgmZ4HiwScDJhB3V5z+ulW4Dq5zq5so4Ul0BW/I36IIgCMUOgEfsH97ixE 3wlCH+gwujlOzG7ryGts6FP+IT5AzNVAvB4YyjsZ8ADoqMzx73XmRyjP7fu+VW8n F8K8cqdJKhhNDUMhgemaqFdwdClHOwQlmnkM7hh5qqa3dPG/JLW4OqQxWHqaBOR4 0ECAPJe8HPtMBl4fTxGtJmykbKY803pjaBejqlaQtFL/Z7fklJCrQPQgEfNlk3jm mgoGmN1MuX98h4BntR3erbMhbTHn2pYYMvIPZS/xvd4Q17+ev3Gzaxu7SlrtSSLr r2UrInpt3skigymS015rMuHxtpmbX7BAU4wmHWZLhPkZ3Fj1BFFlTLZsV5rtjtRM N5rDevzX9Nx/5qVie4ye/UNrypEagFjgdxpUw15VWLmokMZqAQ1/KLdc+Mn0cthx gg6zoKuUDMHAzkKSl6KfzlIw+s55rKHkqh199cNV2AtQgwSNaGs= =vf8E -----END PGP SIGNATURE-----


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds