SUSE-SU-2015:1810-1
Dashboard / Vulnerabilities / SUSE-SU-2015:1810-1
SUSE-SU-2015:1810-1
Summary: Security update for python-Django
Details: This update for python-Django fixes the following security issues: - Prevent Denial-of-service possibility by filling session store. (bsc#937522, CVE-2015-5143) - Prevent Header injection possibility. (bsc#937523, CVE-2015-5144) - A remote denial of service (resource exhaustion) attack against the django session store was fixed in Python Django. This might have allowed remote attackers to exhaust existing web sessions. (bsc#941587, CVE-2015-5963)
References: https://www.suse.com/support/update/announcement/2015/suse-su-20151810-1/, https://bugzilla.suse.com/937522, https://bugzilla.suse.com/937523, https://bugzilla.suse.com/941587, https://www.suse.com/security/cve/CVE-2015-5143, https://www.suse.com/security/cve/CVE-2015-5144, https://www.suse.com/security/cve/CVE-2015-5963
Affected packages
Package
Name: python-Django
Purl: pkg:rpm/suse/python-Django&distro=SUSE%20OpenStack%20Cloud%205
Affected ranges
Type: ECOSYSTEM
Events:
