Executive Summary

Summary
Title New python-django packages fix denial of service
Informations
Name DSA-1905 First vendor Publication 2009-10-10
Vendor Debian Last vendor Modification 2009-10-10
Severity (Vendor) N/A Revision 1

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Cvss Base Score 5 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

The forms library of python-django, a high-level Python web development framework, is using a badly chosen regular expression when validating email addresses and URLs. An attacker can use this to perform denial of service attacks (100% CPU consumption) due to bad backtracking via a specially crafted email address or URL which is validated by the django forms library.

python-django in the oldstable distribution (etch), is not affected by this problem.

For the stable distribution (lenny), this problem has been fixed in version 1.0.2-1+lenny2.

For the testing distribution (squeeze), this problem will be fixed soon.

For the unstable distribution (sid), this problem has been fixed in version 1.1.1-1.

We recommend that you upgrade your python-django packages.

Original Source

Url : http://www.debian.org/security/2009/dsa-1905

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 2

OpenVAS Exploits

Date Description
2009-12-14 Name : Mandriva Security Advisory MDVSA-2009:276-1 (python-django)
File : nvt/mdksa_2009_276_1.nasl
2009-10-29 Name : Django Forms Library Algorithmic Complexity Vulnerability
File : nvt/secpod_django_algorithmic_complexity_vuln.nasl
2009-10-19 Name : Debian Security Advisory DSA 1905-1 (python-django)
File : nvt/deb_1905_1.nasl
2009-10-19 Name : Fedora Core 11 FEDORA-2009-10390 (Django)
File : nvt/fcore_2009_10390.nasl
2009-10-19 Name : django -- denial-of-service attack
File : nvt/freebsd_py23-django1.nasl
2009-10-19 Name : Mandrake Security Advisory MDVSA-2009:276 (python-django)
File : nvt/mdksa_2009_276.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
58832 Django Forms Library Multiple Field RegEx Handling DoS

Django contains a flaw that may allow a remote denial of service. The issue is triggered when a malicious user puts a specially crafted email address or URL in any of the fields in the form library, and will result in loss of availability for the platform.

Nessus® Vulnerability Scanner

Date Description
2010-02-24 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-1905.nasl - Type : ACT_GATHER_INFO
2009-10-19 Name : The remote FreeBSD host is missing one or more security-related updates.
File : freebsd_pkg_87917d6fba7611debac2001a4d563a0f.nasl - Type : ACT_GATHER_INFO
2009-10-15 Name : The remote Mandriva Linux host is missing a security update.
File : mandriva_MDVSA-2009-276.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2014-02-17 11:28:53
  • Multiple Updates