Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2007-5712 | First vendor Publication | 2007-10-30 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:H/Au:N/C:N/I:N/A:P) | |||
---|---|---|---|
Cvss Base Score | 2.6 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | High |
Cvss Expoit Score | 4.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The internationalization (i18n) framework in Django 0.91, 0.95, 0.95.1, and 0.96, and as used in other products such as PyLucid, when the USE_I18N option and the i18n component are enabled, allows remote attackers to cause a denial of service (memory consumption) via many HTTP requests with large Accept-Language headers. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5712 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-399 | Resource Management Errors |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:18143 | |||
Oval ID: | oval:org.mitre.oval:def:18143 | ||
Title: | DSA-1640-1 python-django - cross site request forgery | ||
Description: | Simon Willison discovered that in Django, a Python web framework, the feature to retain HTTP POST data during user reauthentication allowed a remote attacker to perform unauthorised modification of data through cross site request forgery. This is possible regardless of the Django plugin to prevent cross site request forgery being enabled. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1640-1 CVE-2008-3909 CVE-2007-5712 | Version: | 7 |
Platform(s): | Debian GNU/Linux 4.0 | Product(s): | python-django |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:8091 | |||
Oval ID: | oval:org.mitre.oval:def:8091 | ||
Title: | DSA-1640 python-django -- several vulnerabilities | ||
Description: | Simon Willison discovered that in Django, a Python web framework, the feature to retain HTTP POST data during user reauthentication allowed a remote attacker to perform unauthorised modification of data through cross site request forgery. This is possible regardless of the Django plugin to prevent cross site request forgery being enabled. The Common Vulnerabilities and Exposures project identifies this issue as CVE-2008-3909. In this update the affected feature is disabled; this is in accordance with upstream’s preferred solution for this situation. This update takes the opportunity to also include a relatively minor denial of service attack in the internationalisation framework, known as CVE-2007-5712. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1640 CVE-2008-3909 CVE-2007-5712 | Version: | 3 |
Platform(s): | Debian GNU/Linux 4.0 | Product(s): | python-django |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 4 |
OpenVAS Exploits
Date | Description |
---|---|
2009-02-27 | Name : Fedora Update for Django FEDORA-2007-2788 File : nvt/gb_fedora_2007_2788_Django_fc8.nasl |
2009-02-27 | Name : Fedora Update for Django FEDORA-2007-3157 File : nvt/gb_fedora_2007_3157_Django_fc7.nasl |
2009-02-17 | Name : Fedora Update for Django FEDORA-2008-4191 File : nvt/gb_fedora_2008_4191_Django_fc7.nasl |
2008-09-24 | Name : Debian Security Advisory DSA 1640-1 (python-django) File : nvt/deb_1640_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
38905 | Django Internationalization Framework USE_I18N Option Multiple HTTP Request R... |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2008-09-23 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1640.nasl - Type : ACT_GATHER_INFO |
2008-05-22 | Name : The remote Fedora host is missing a security update. File : fedora_2008-4191.nasl - Type : ACT_GATHER_INFO |
2007-11-12 | Name : The remote Fedora host is missing a security update. File : fedora_2007-2788.nasl - Type : ACT_GATHER_INFO |
2007-11-12 | Name : The remote Fedora host is missing a security update. File : fedora_2007-3157.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:15:57 |
|
2024-11-28 12:13:53 |
|
2021-05-04 12:06:36 |
|
2021-04-22 01:07:07 |
|
2020-05-23 00:20:42 |
|
2017-07-29 12:02:38 |
|
2016-04-26 16:45:36 |
|
2014-02-17 10:42:24 |
|
2013-05-11 10:40:43 |
|