[ubuntu/bionic-security] python-django 1:1.11.11-1ubuntu1.7 (Accepted)

Alex Murray alex.murray at canonical.com
Tue Feb 4 02:25:00 UTC 2020


python-django (1:1.11.11-1ubuntu1.7) bionic-security; urgency=medium

  * SECURITY UPDATE: Possible SQL injection in the postgres aggregates
    StringAgg function
    - debian/patches/CVE-2020-7471.patch: Update
      django/contrib/postgres/aggregates/general.py to escape delimited
      parameter to the StringAgg function. Upstream patch.
    - CVE-2020-7471

Date: 2020-02-03 11:54:13.860410+00:00
Changed-By: Alex Murray <alex.murray at canonical.com>
https://launchpad.net/ubuntu/+source/python-django/1:1.11.11-1ubuntu1.7
-------------- next part --------------
Sorry, changesfile not available.


More information about the Bionic-changes mailing list