[ubuntu/lucid-security] python-django 1.1.1-2ubuntu1.9 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Tue Sep 24 15:30:09 UTC 2013


python-django (1.1.1-2ubuntu1.9) lucid-security; urgency=low

  * SECURITY UPDATE: denial of service via long passwords (LP: #1225784)
    - debian/patches/CVE-2013-1443.patch: enforce a maximum password length
      in django/contrib/auth/forms.py, django/contrib/auth/models.py,
      django/contrib/auth/tests/basic.py.
    - CVE-2013-1443
  * SECURITY UPDATE: directory traversal with ssi template tag
    - debian/patches/CVE-2013-4315.patch: properly check absolute path in
      django/template/defaulttags.py,
      tests/regressiontests/templates/tests.py,
      tests/regressiontests/templates/templates/*.
    - CVE-2013-4315
  * SECURITY UPDATE: possible XSS via is_safe_url
    - debian/patches/security-is_safe_url.patch: properly reject URLs which
      specify a scheme other then HTTP or HTTPS.
    - https://www.djangoproject.com/weblog/2013/aug/13/security-releases-issued/
    - No CVE number

Date: 2013-09-20 15:07:14.398744+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/lucid/+source/python-django/1.1.1-2ubuntu1.9
-------------- next part --------------
Sorry, changesfile not available.


More information about the Lucid-changes mailing list