[ubuntu/eoan-security] python-django 1:1.11.22-1ubuntu1.2 (Accepted)

Alex Murray alex.murray at canonical.com
Tue Feb 4 02:24:58 UTC 2020


python-django (1:1.11.22-1ubuntu1.2) eoan-security; urgency=medium

  * SECURITY UPDATE: Possible SQL injection in the postgres aggregates
    StringAgg function
    - debian/patches/CVE-2020-7471.patch: Update
      django/contrib/postgres/aggregates/general.py to escape delimited
      parameter to the StringAgg function. Upstream patch.
    - CVE-2020-7471

Date: 2020-02-03 11:42:14.325743+00:00
Changed-By: Alex Murray <alex.murray at canonical.com>
https://launchpad.net/ubuntu/+source/python-django/1:1.11.22-1ubuntu1.2
-------------- next part --------------
Sorry, changesfile not available.


More information about the Eoan-changes mailing list