Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

django: security update to 2.1.11 #1938

Closed
1 task done
l2dy opened this issue Aug 4, 2019 · 1 comment
Closed
1 task done

django: security update to 2.1.11 #1938

l2dy opened this issue Aug 4, 2019 · 1 comment
Labels
security Topic/issue involves a security issue/fixed upgrade Topic/issue involves a package upgrade

Comments

@l2dy
Copy link
Member

l2dy commented Aug 4, 2019

CVE IDs: CVE-2019-14232, CVE-2019-14233, CVE-2019-14234, CVE-2019-14235

Other security advisory IDs: USN-4084-1, ASA-201908-2, openSUSE-SU-2019:1839-1, DSA-4498-1

Descriptions:
It was discovered that Django incorrectly handled the Truncator function. A
remote attacker could possibly use this issue to cause Django to consume
resources, leading to a denial of service. (CVE-2019-14232)

It was discovered that Django incorrectly handled the strip_tags function.
A remote attacker could possibly use this issue to cause Django to consume
resources, leading to a denial of service. (CVE-2019-14233)

It was discovered that Django incorrectly handled certain lookups in the
PostgreSQL support. A remote attacker could possibly use this issue to
perform SQL injection attacks. (CVE-2019-14234)

It was discovered that Django incorrectly handled certain invalid UTF-8
octet sequences. A remote attacker could possibly use this issue to cause
Django to consume resources, leading to a denial of service.
(CVE-2019-14235)

https://www.djangoproject.com/weblog/2019/aug/01/security-releases/

Architectural progress:

  • Architecture-independent noarch -->
@l2dy l2dy added upgrade Topic/issue involves a package upgrade security Topic/issue involves a security issue/fixed to-stable labels Aug 4, 2019
@KexyBiscuit KexyBiscuit added this to the Summer 2019 milestone Aug 13, 2019
MingcongBai added a commit that referenced this issue Sep 2, 2019
@KexyBiscuit
Copy link
Member

Use AOSA-2019-0203.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security Topic/issue involves a security issue/fixed upgrade Topic/issue involves a package upgrade
Projects
None yet
Development

No branches or pull requests

2 participants