Debian alert DLA-4006-1 (python-django)
From: | Chris Lamb <lamby@debian.org> | |
To: | debian-lts-announce@lists.debian.org | |
Subject: | [SECURITY] [DLA 4006-1] python-django security update | |
Date: | Tue, 31 Dec 2024 16:01:44 +0000 | |
Message-ID: | <173565706647.377616.3498062011138837315@copycat> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4006-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Chris Lamb December 31, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : python-django Version : 2:2.2.28-1~deb11u3 CVE ID : CVE-2024-53907 It was discovered that there was a potential Denial of Service (DoS) vulnerability, in Django, a popular Python-based web development framework. The strip_tags() method and striptags template filter were subject to a potential denial-of-service attack via certain inputs containing large sequences of nested incomplete HTML entities. For Debian 11 bullseye, this problem has been fixed in version 2:2.2.28-1~deb11u3. We recommend that you upgrade your python-django packages. For the detailed security status of python-django please refer to its security tracker page at: https://security-tracker.debian.org/tracker/python-django Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmd0BmgACgkQHpU+J9Qx HlhLFhAAwcroO4+AxOc6RTndU6qJgzxwvCmBcT7g8bynBfFKvEQ/0Ybmk2Y6hM6q wU6493V1M/TjKEpzWuytsBo0lTMHqMuXvne/iTuNNNoru0GIvCO2NfkAQNvMtUiY FKpWFUMoOx6ezbuvr/wWl4T94vuzZYJhajXoyDffCb6iEOdO3lbbbG0fEuuqkQq1 0BYrgocgmZ4HiwScDJhB3V5z+ulW4Dq5zq5so4Ul0BW/I36IIgCMUOgEfsH97ixE 3wlCH+gwujlOzG7ryGts6FP+IT5AzNVAvB4YyjsZ8ADoqMzx73XmRyjP7fu+VW8n F8K8cqdJKhhNDUMhgemaqFdwdClHOwQlmnkM7hh5qqa3dPG/JLW4OqQxWHqaBOR4 0ECAPJe8HPtMBl4fTxGtJmykbKY803pjaBejqlaQtFL/Z7fklJCrQPQgEfNlk3jm mgoGmN1MuX98h4BntR3erbMhbTHn2pYYMvIPZS/xvd4Q17+ev3Gzaxu7SlrtSSLr r2UrInpt3skigymS015rMuHxtpmbX7BAU4wmHWZLhPkZ3Fj1BFFlTLZsV5rtjtRM N5rDevzX9Nx/5qVie4ye/UNrypEagFjgdxpUw15VWLmokMZqAQ1/KLdc+Mn0cthx gg6zoKuUDMHAzkKSl6KfzlIw+s55rKHkqh199cNV2AtQgwSNaGs= =vf8E -----END PGP SIGNATURE-----