Lucene search

K
cveRedhatCVE-2012-3444
HistoryJul 31, 2012 - 5:55 p.m.

CVE-2012-3444

2012-07-3117:55:04
CWE-119
redhat
web.nvd.nist.gov
55
django
get_image_dimensions
image-handling
vulnerability
cve-2012-3444
denial of service
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.3

Confidence

Low

EPSS

0.02

Percentile

88.9%

The get_image_dimensions function in the image-handling functionality in Django before 1.3.2 and 1.4.x before 1.4.1 uses a constant chunk size in all attempts to determine dimensions, which allows remote attackers to cause a denial of service (process or thread consumption) via a large TIFF image.

Affected configurations

Nvd
Node
djangoprojectdjangoRange≀1.3
OR
djangoprojectdjangoMatch0.95
OR
djangoprojectdjangoMatch0.96
OR
djangoprojectdjangoMatch1.0
OR
djangoprojectdjangoMatch1.0alpha1
OR
djangoprojectdjangoMatch1.0alpha2
OR
djangoprojectdjangoMatch1.0beta
OR
djangoprojectdjangoMatch1.0beta2
OR
djangoprojectdjangoMatch1.0.1
OR
djangoprojectdjangoMatch1.0.2
OR
djangoprojectdjangoMatch1.1
OR
djangoprojectdjangoMatch1.1alpha1
OR
djangoprojectdjangoMatch1.1beta1
OR
djangoprojectdjangoMatch1.1rc1
OR
djangoprojectdjangoMatch1.1.2
OR
djangoprojectdjangoMatch1.1.3
OR
djangoprojectdjangoMatch1.1.4
OR
djangoprojectdjangoMatch1.2
OR
djangoprojectdjangoMatch1.2beta1
OR
djangoprojectdjangoMatch1.2rc1
OR
djangoprojectdjangoMatch1.2-alpha1
OR
djangoprojectdjangoMatch1.2.2
OR
djangoprojectdjangoMatch1.2.4
OR
djangoprojectdjangoMatch1.2.5
OR
djangoprojectdjangoMatch1.2.6
OR
djangoprojectdjangoMatch1.2.7
OR
djangoprojectdjangoMatch1.3alpha1
OR
djangoprojectdjangoMatch1.3beta1
OR
djangoprojectdjangoMatch1.4
VendorProductVersionCPE
djangoprojectdjango1.0.2cpe:/a:djangoproject:django:1.0.2:::
djangoprojectdjango1.1.4cpe:/a:djangoproject:django:1.1.4:::
djangoprojectdjango1.2cpe:/a:djangoproject:django:1.2:rc1::
djangoprojectdjango1.2cpe:/a:djangoproject:django:1.2:beta1::
djangoprojectdjango1.2.5cpe:/a:djangoproject:django:1.2.5:::
djangoprojectdjango1.0.1cpe:/a:djangoproject:django:1.0.1:::
djangoprojectdjango1.0cpe:/a:djangoproject:django:1.0:::
djangoprojectdjango1.1.3cpe:/a:djangoproject:django:1.1.3:::
djangoprojectdjango1.1cpe:/a:djangoproject:django:1.1:beta1::
djangoprojectdjango1.3cpe:/a:djangoproject:django:1.3:alpha1::
Rows per page:
1-10 of 291

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.3

Confidence

Low

EPSS

0.02

Percentile

88.9%