SUSE-SU-2015:0695-1
Dashboard / Vulnerabilities / SUSE-SU-2015:0695-1
SUSE-SU-2015:0695-1
Summary: Security update for python-django
Details: python-django was updated to 1.5.10 fixing bugs and security issues: * Prevented reverse() from generating URLs pointing to other hosts to prevent phishing attacks. (bnc#893087, CVE-2014-0480) * Removed O(n) algorithm when uploading duplicate file names to fix file upload denial of service. (bnc#893088, CVE-2014-0481) * Modified RemoteUserMiddleware to logout on REMOTE_USE change to prevent session hijacking. (bnc#893089, CVE-2014-0482) * Prevented data leakage in contrib.admin via query string manipulation. (bnc#893090, CVE-2014-0483) Security Issues: * CVE-2014-0480 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0480> * CVE-2014-0481 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0481> * CVE-2014-0482 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0482> * CVE-2014-0483 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0483>
References: https://www.suse.com/support/update/announcement/2015/suse-su-20150695-1/, https://bugzilla.suse.com/893087, https://bugzilla.suse.com/893088, https://bugzilla.suse.com/893089, https://bugzilla.suse.com/893090, https://bugzilla.suse.com/913053, https://bugzilla.suse.com/913054, https://bugzilla.suse.com/913055, https://bugzilla.suse.com/913056, https://bugzilla.suse.com/914706, https://bugzilla.suse.com/923176, https://www.suse.com/security/cve/CVE-2014-0480, https://www.suse.com/security/cve/CVE-2014-0481, https://www.suse.com/security/cve/CVE-2014-0482, https://www.suse.com/security/cve/CVE-2014-0483, https://www.suse.com/security/cve/CVE-2015-0219, https://www.suse.com/security/cve/CVE-2015-0220, https://www.suse.com/security/cve/CVE-2015-0221, https://www.suse.com/security/cve/CVE-2015-0222, https://www.suse.com/security/cve/CVE-2015-2316, https://www.suse.com/security/cve/CVE-2015-2317
