Executive Summary



This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Summary
Title python-django security update
Informations
Name DSA-2634 First vendor Publication 2013-02-27
Vendor Debian Last vendor Modification 2013-02-27
Severity (Vendor) N/A Revision 1

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:N)
Cvss Base Score 6.4 Attack Range Network
Cvss Impact Score 4.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Several vulnerabilities have been discovered in python-django, a high-level python web development framework. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2012-4520

James Kettle discovered that django did not properly filter the HTTP Host header when processing certain requests. An attacker could exploit this to generate and cause parts of django, particularly the password-reset mechanism, to display arbitrary URLs to users.

CVE-2013-0305

Orange Tsai discovered that the bundled administrative interface of django could expose supposedly-hidden information via its history log.

CVE-2013-0306

Mozilla discovered that an attacker can abuse django's tracking of the number of forms in a formset to cause a denial-of-service attack due to extreme memory consumption.

CVE-2013-1665

Michael Koziarski discovered that django's XML deserialization is vulnerable to entity-expansion and external-entity/DTD attacks.

For the stable distribution (squeeze), these problems have been fixed in version 1.2.3-3+squeeze5.

For the testing distribution (wheezy), these problems will be fixed soon.

For the unstable distribution (sid), these problems have been fixed in version 1.4.4-1.

We recommend that you upgrade your python-django packages.

Original Source

Url : http://www.debian.org/security/2013/dsa-2634

CWE : Common Weakness Enumeration

% Id Name
50 % CWE-200 Information Exposure
25 % CWE-189 Numeric Errors (CWE/SANS Top 25)
25 % CWE-20 Improper Input Validation

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:17354
 
Oval ID: oval:org.mitre.oval:def:17354
Title: USN-1730-1 -- OpenStack Keystone vulnerabilities
Description: Keystone could be made to crash or expose sensitive information over the network.
Family: unix Class: patch
Reference(s): usn-1730-1
CVE-2013-0282
CVE-2013-1664
CVE-2013-1665
Version: 7
Platform(s): Ubuntu 12.10
Ubuntu 12.04
Product(s): keystone
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:18138
 
Oval ID: oval:org.mitre.oval:def:18138
Title: USN-1757-1 -- python-django vulnerabilities
Description: Several security issues were fixed in Django.
Family: unix Class: patch
Reference(s): USN-1757-1
CVE-2012-4520
CVE-2013-0305
CVE-2013-0306
CVE-2013-1664
CVE-2013-1665
Version: 7
Platform(s): Ubuntu 12.10
Ubuntu 12.04
Ubuntu 11.10
Ubuntu 10.04
Product(s): python-django
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:18150
 
Oval ID: oval:org.mitre.oval:def:18150
Title: USN-1632-1 -- python-django vulnerability
Description: Django could be made to expose sensitive information over the network.
Family: unix Class: patch
Reference(s): USN-1632-1
CVE-2012-4520
Version: 7
Platform(s): Ubuntu 12.10
Ubuntu 12.04
Ubuntu 11.10
Ubuntu 10.04
Product(s): python-django
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:19205
 
Oval ID: oval:org.mitre.oval:def:19205
Title: DSA-2634-1 python-django - several vulnerabilities
Description: Several vulnerabilities have been discovered in Django, a high-level Python web development framework.
Family: unix Class: patch
Reference(s): DSA-2634-1
CVE-2012-4520
CVE-2013-0305
CVE-2013-0306
CVE-2013-1665
Version: 5
Platform(s): Debian GNU/Linux 6.0
Debian GNU/kFreeBSD 6.0
Product(s): python-django
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 13
Application 1
Application 1
Os 4

OpenVAS Exploits

Date Description
2012-12-26 Name : Mandriva Update for python-django MDVSA-2012:181 (python-django)
File : nvt/gb_mandriva_MDVSA_2012_181.nasl
2012-11-19 Name : Ubuntu Update for python-django USN-1632-1
File : nvt/gb_ubuntu_USN_1632_1.nasl
2012-11-02 Name : Fedora Update for Django FEDORA-2012-16417
File : nvt/gb_fedora_2012_16417_Django_fc16.nasl
2012-11-02 Name : Fedora Update for Django FEDORA-2012-16440
File : nvt/gb_fedora_2012_16440_Django_fc17.nasl
2012-10-29 Name : FreeBSD Ports: django
File : nvt/freebsd_django.nasl

Snort® IPS/IDS

Date Description
2014-03-15 XML exponential entity expansion attack attempt
RuleID : 29800 - Revision : 4 - Type : FILE-OTHER
2014-01-10 XML exponential entity expansion attack attempt
RuleID : 27096 - Revision : 5 - Type : FILE-OTHER

Nessus® Vulnerability Scanner

Date Description
2014-06-13 Name : The remote openSUSE host is missing a security update.
File : openSUSE-2013-237.nasl - Type : ACT_GATHER_INFO
2014-06-13 Name : The remote openSUSE host is missing a security update.
File : openSUSE-2013-589.nasl - Type : ACT_GATHER_INFO
2013-03-13 Name : The remote Fedora host is missing a security update.
File : fedora_2013-2843.nasl - Type : ACT_GATHER_INFO
2013-03-13 Name : The remote Fedora host is missing a security update.
File : fedora_2013-2874.nasl - Type : ACT_GATHER_INFO
2013-03-08 Name : The remote Ubuntu host is missing a security-related patch.
File : ubuntu_USN-1757-1.nasl - Type : ACT_GATHER_INFO
2013-03-05 Name : The remote Fedora host is missing a security update.
File : fedora_2013-2916.nasl - Type : ACT_GATHER_INFO
2013-02-27 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-2634.nasl - Type : ACT_GATHER_INFO
2013-02-25 Name : The remote FreeBSD host is missing one or more security-related updates.
File : freebsd_pkg_21c59f5e7cc511e29c11080027a5ec9a.nasl - Type : ACT_GATHER_INFO
2013-02-21 Name : The remote Ubuntu host is missing a security-related patch.
File : ubuntu_USN-1730-1.nasl - Type : ACT_GATHER_INFO
2012-12-20 Name : The remote Mandriva Linux host is missing a security update.
File : mandriva_MDVSA-2012-181.nasl - Type : ACT_GATHER_INFO
2012-11-16 Name : The remote Ubuntu host is missing a security-related patch.
File : ubuntu_USN-1632-1.nasl - Type : ACT_GATHER_INFO
2012-10-31 Name : The remote Fedora host is missing a security update.
File : fedora_2012-16440.nasl - Type : ACT_GATHER_INFO
2012-10-30 Name : The remote Fedora host is missing a security update.
File : fedora_2012-16417.nasl - Type : ACT_GATHER_INFO
2012-10-26 Name : The remote FreeBSD host is missing one or more security-related updates.
File : freebsd_pkg_5f326d751db911e2bc8fd0df9acfd7e5.nasl - Type : ACT_GATHER_INFO
2012-10-24 Name : The remote Fedora host is missing a security update.
File : fedora_2012-16406.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
2
3
Date Informations
2014-02-17 11:31:41
  • Multiple Updates
2013-05-02 21:20:21
  • Multiple Updates
2013-04-03 13:20:37
  • Multiple Updates
2013-02-27 05:17:34
  • First insertion