|
|
Log in / Subscribe / Register

python-django: two vulnerabilities

Package(s):python-django CVE #(s):CVE-2016-2512 CVE-2016-2513
Created:March 2, 2016 Updated:April 8, 2016
Description: From the Ubuntu advisory:

Mark Striemer discovered that Django incorrectly handled user-supplied redirect URLs containing basic authentication credentials. A remote attacker could possibly use this issue to perform a cross-site scripting attack or a malicious redirect. (CVE-2016-2512)

Sjoerd Job Postmus discovered that Django incorrectly handled timing when doing password hashing operations. A remote attacker could possibly use this issue to perform user enumeration. (CVE-2016-2513)

Alerts:
Debian DSA-3544-1 python-django 2016-04-07
Red Hat RHSA-2016:0502-01 python-django 2016-03-24
Red Hat RHSA-2016:0506-01 python-django 2016-03-24
Red Hat RHSA-2016:0505-01 python-django 2016-03-24
Red Hat RHSA-2016:0504-01 python-django 2016-03-24
Red Hat RHSA-2016:0503-01 python-django 2016-03-24
Fedora FEDORA-2016-b004d6d8f7 python-django 2016-03-17
Fedora FEDORA-2016-11183ea08d python-django 2016-03-17
Ubuntu USN-2915-3 python-django 2016-03-07
Ubuntu USN-2915-2 python-django 2016-03-07
Mageia MGASA-2016-0096 python-django 2016-03-07
Ubuntu USN-2915-1 python-django 2016-03-01

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds