MGASA-2016-0096
Dashboard / Vulnerabilities / MGASA-2016-0096
Summary: Updated python-django packages fix security vulnerability
Details: Mark Striemer discovered that Django incorrectly handled user-supplied redirect URLs containing basic authentication credentials. A remote attacker could possibly use this issue to perform a cross-site scripting attack or a malicious redirect. (CVE-2016-2512) Sjoerd Job Postmus discovered that Django incorrectly handled timing when doing password hashing operations. A remote attacker could possibly use this issue to perform user enumeration. (CVE-2016-2513)
References: https://advisories.mageia.org/MGASA-2016-0096.html, https://bugs.mageia.org/show_bug.cgi?id=17860, http://www.ubuntu.com/usn/usn-2915-1/, https://www.djangoproject.com/weblog/2016/mar/01/security-releases/
Affected packages
Package
Name: python-django
Purl: pkg:rpm/mageia/python-django?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
