Lucene search

K
ubuntuUbuntuUSN-1967-1
HistorySep 24, 2013 - 12:00 a.m.

Django vulnerabilities

2013-09-2400:00:00
ubuntu.com
45

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0.013

Percentile

85.8%

Releases

  • Ubuntu 13.04
  • Ubuntu 12.10
  • Ubuntu 12.04
  • Ubuntu 10.04

Packages

  • python-django - High-level Python web development framework

Details

It was discovered that Django incorrectly handled large passwords. A remote
attacker could use this issue to consume resources, resulting in a denial
of service. (CVE-2013-1443)

It was discovered that Django incorrectly handled ssi templates. An
attacker could use this issue to read arbitrary files. (CVE-2013-4315)

It was discovered that the Django is_safe_url utility function did not
restrict redirects to certain schemes. An attacker could possibly use this
issue to perform a cross-site scripting attack.

OSVersionArchitecturePackageVersionFilename
Ubuntu13.04noarchpython-django<ย 1.4.5-1ubuntu0.1UNKNOWN
Ubuntu13.04noarchpython-django-doc<ย 1.4.5-1ubuntu0.1UNKNOWN
Ubuntu12.10noarchpython-django<ย 1.4.1-2ubuntu0.4UNKNOWN
Ubuntu12.10noarchpython-django-doc<ย 1.4.1-2ubuntu0.4UNKNOWN
Ubuntu12.04noarchpython-django<ย 1.3.1-4ubuntu1.8UNKNOWN
Ubuntu12.04noarchpython-django-doc<ย 1.3.1-4ubuntu1.8UNKNOWN
Ubuntu10.04noarchpython-django<ย 1.1.1-2ubuntu1.9UNKNOWN
Ubuntu10.04noarchpython-django-doc<ย 1.1.1-2ubuntu1.9UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0.013

Percentile

85.8%