Lucene search

K
cveRedhatCVE-2013-0306
HistoryMay 02, 2013 - 2:55 p.m.

CVE-2013-0306

2013-05-0214:55:05
CWE-189
redhat
web.nvd.nist.gov
64
cve-2013-0306
django
form library
remote attackers
resource limits
denial of service

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.5

Confidence

Low

EPSS

0.009

Percentile

82.9%

The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_num parameter.

Affected configurations

Nvd
Node
djangoprojectdjangoMatch1.3
OR
djangoprojectdjangoMatch1.3alpha1
OR
djangoprojectdjangoMatch1.3beta1
OR
djangoprojectdjangoMatch1.3.1
OR
djangoprojectdjangoMatch1.3.2
OR
djangoprojectdjangoMatch1.3.3
Node
djangoprojectdjangoMatch1.4
OR
djangoprojectdjangoMatch1.4alpha
OR
djangoprojectdjangoMatch1.4beta
OR
djangoprojectdjangoMatch1.4.1
OR
djangoprojectdjangoMatch1.4.2
Node
djangoprojectdjangoMatch1.5alpha
OR
djangoprojectdjangoMatch1.5beta
Node
canonicalubuntu_linuxMatch10.04-lts
OR
canonicalubuntu_linuxMatch11.10
OR
canonicalubuntu_linuxMatch12.04-lts
OR
canonicalubuntu_linuxMatch12.10
VendorProductVersionCPE
djangoprojectdjango1.3cpe:/a:djangoproject:django:1.3:::
djangoprojectdjango1.3cpe:/a:djangoproject:django:1.3:alpha1::
djangoprojectdjango1.3.2cpe:/a:djangoproject:django:1.3.2:::
djangoprojectdjango1.3.1cpe:/a:djangoproject:django:1.3.1:::
djangoprojectdjango1.3cpe:/a:djangoproject:django:1.3:beta1::
djangoprojectdjango1.3.3cpe:/a:djangoproject:django:1.3.3:::

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.5

Confidence

Low

EPSS

0.009

Percentile

82.9%