USN-2347-1
Dashboard / Vulnerabilities / USN-2347-1
USN-2347-1
Summary: python-django vulnerabilities
Details: Florian Apolloner discovered that Django incorrectly validated URLs. A remote attacker could use this issue to conduct phishing attacks. (CVE-2014-0480) David Wilson discovered that Django incorrectly handled file name generation. A remote attacker could use this issue to cause Django to consume resources, resulting in a denial of service. (CVE-2014-0481) David Greisen discovered that Django incorrectly handled certain headers in contrib.auth.middleware.RemoteUserMiddleware. A remote authenticated user could use this issue to hijack web sessions. (CVE-2014-0482) Collin Anderson discovered that Django incorrectly checked if a field represented a relationship between models in the administrative interface. A remote authenticated user could use this issue to possibly obtain sensitive information. (CVE-2014-0483)
References: https://ubuntu.com/security/notices/USN-2347-1, https://ubuntu.com/security/CVE-2014-0480, https://ubuntu.com/security/CVE-2014-0481, https://ubuntu.com/security/CVE-2014-0482, https://ubuntu.com/security/CVE-2014-0483
Affected packages
Package
Name: python-django
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
