Lucene search

K
cveRedhatCVE-2012-3443
HistoryJul 31, 2012 - 5:55 p.m.

CVE-2012-3443

2012-07-3117:55:04
CWE-20
redhat
web.nvd.nist.gov
62
cve-2012-3443
django
forms
imagefield
security
vulnerability
denial of service

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.2

Confidence

Low

EPSS

0.021

Percentile

89.1%

The django.forms.ImageField class in the form system in Django before 1.3.2 and 1.4.x before 1.4.1 completely decompresses image data during image validation, which allows remote attackers to cause a denial of service (memory consumption) by uploading an image file.

Affected configurations

Nvd
Node
djangoprojectdjangoRange≀1.3
OR
djangoprojectdjangoMatch0.95
OR
djangoprojectdjangoMatch0.96
OR
djangoprojectdjangoMatch1.0
OR
djangoprojectdjangoMatch1.0alpha1
OR
djangoprojectdjangoMatch1.0alpha2
OR
djangoprojectdjangoMatch1.0beta
OR
djangoprojectdjangoMatch1.0beta2
OR
djangoprojectdjangoMatch1.0.1
OR
djangoprojectdjangoMatch1.0.2
OR
djangoprojectdjangoMatch1.1
OR
djangoprojectdjangoMatch1.1alpha1
OR
djangoprojectdjangoMatch1.1beta1
OR
djangoprojectdjangoMatch1.1rc1
OR
djangoprojectdjangoMatch1.1.2
OR
djangoprojectdjangoMatch1.1.3
OR
djangoprojectdjangoMatch1.1.4
OR
djangoprojectdjangoMatch1.2
OR
djangoprojectdjangoMatch1.2beta1
OR
djangoprojectdjangoMatch1.2rc1
OR
djangoprojectdjangoMatch1.2-alpha1
OR
djangoprojectdjangoMatch1.2.2
OR
djangoprojectdjangoMatch1.2.4
OR
djangoprojectdjangoMatch1.2.5
OR
djangoprojectdjangoMatch1.2.6
OR
djangoprojectdjangoMatch1.2.7
OR
djangoprojectdjangoMatch1.3alpha1
OR
djangoprojectdjangoMatch1.3beta1
OR
djangoprojectdjangoMatch1.4
VendorProductVersionCPE
djangoprojectdjango*cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
djangoprojectdjango0.95cpe:2.3:a:djangoproject:django:0.95:*:*:*:*:*:*:*
djangoprojectdjango0.96cpe:2.3:a:djangoproject:django:0.96:*:*:*:*:*:*:*
djangoprojectdjango1.0cpe:2.3:a:djangoproject:django:1.0:*:*:*:*:*:*:*
djangoprojectdjango1.0cpe:2.3:a:djangoproject:django:1.0:alpha1:*:*:*:*:*:*
djangoprojectdjango1.0cpe:2.3:a:djangoproject:django:1.0:alpha2:*:*:*:*:*:*
djangoprojectdjango1.0cpe:2.3:a:djangoproject:django:1.0:beta:*:*:*:*:*:*
djangoprojectdjango1.0cpe:2.3:a:djangoproject:django:1.0:beta2:*:*:*:*:*:*
djangoprojectdjango1.0.1cpe:2.3:a:djangoproject:django:1.0.1:*:*:*:*:*:*:*
djangoprojectdjango1.0.2cpe:2.3:a:djangoproject:django:1.0.2:*:*:*:*:*:*:*
Rows per page:
1-10 of 291

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.2

Confidence

Low

EPSS

0.021

Percentile

89.1%