[ubuntu/eoan-security] python-django 1:1.11.22-1ubuntu1.2 (Accepted)

Alex Murray alex.murray at canonical.com
Tue Feb 4 02:24:58 UTC 2020

python-django (1:1.11.22-1ubuntu1.2) eoan-security; urgency=medium

  * SECURITY UPDATE: Possible SQL injection in the postgres aggregates
    StringAgg function
    - debian/patches/CVE-2020-7471.patch: Update
      django/contrib/postgres/aggregates/general.py to escape delimited
      parameter to the StringAgg function. Upstream patch.
    - CVE-2020-7471

Date: 2020-02-03 11:42:14.325743+00:00
Changed-By: Alex Murray <alex.murray at canonical.com>
-------------- next part --------------
Sorry, changesfile not available.

More information about the Eoan-changes mailing list