Executive Summary
Informations | |||
---|---|---|---|
Name | MDVSA-2009:276-1 | First vendor Publication | 2009-12-08 |
Vendor | Mandriva | Last vendor Modification | 2009-12-08 |
Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Multiple vulnerabilities has been found and corrected in python-django: The Admin media handler in core/servers/basehttp.py in Django 1.0 and 0.96 does not properly map URL requests to expected static media files, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a crafted URL (CVE-2009-2659). Algorithmic complexity vulnerability in the forms library in Django 1.0 before 1.0.4 and 1.1 before 1.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a crafted (1) EmailField (email address) or (2) URLField (URL) that triggers a large amount of backtracking in a regular expression (CVE-2009-3695). The versions of Django shipping with Mandriva Linux have been updated to the latest patched version that include the fix for this issue. In addition, they provide other bug fixes. Update: Packages for 2008.0 are being provided due to extended support for Corporate products. |
Original Source
Url : http://www.mandriva.com/security/advisories?name=MDVSA-2009:276-1 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE/SANS Top 25) |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 2 | |
Application | 2 |
OpenVAS Exploits
Date | Description |
---|---|
2009-12-14 | Name : Mandriva Security Advisory MDVSA-2009:276-1 (python-django) File : nvt/mdksa_2009_276_1.nasl |
2009-10-29 | Name : Django Forms Library Algorithmic Complexity Vulnerability File : nvt/secpod_django_algorithmic_complexity_vuln.nasl |
2009-10-19 | Name : Debian Security Advisory DSA 1905-1 (python-django) File : nvt/deb_1905_1.nasl |
2009-10-19 | Name : Fedora Core 11 FEDORA-2009-10390 (Django) File : nvt/fcore_2009_10390.nasl |
2009-10-19 | Name : django -- denial-of-service attack File : nvt/freebsd_py23-django1.nasl |
2009-10-19 | Name : Mandrake Security Advisory MDVSA-2009:275 (python-django) File : nvt/mdksa_2009_275.nasl |
2009-10-19 | Name : Mandrake Security Advisory MDVSA-2009:276 (python-django) File : nvt/mdksa_2009_276.nasl |
2009-08-17 | Name : Fedora Core 10 FEDORA-2009-8169 (Django) File : nvt/fcore_2009_8169.nasl |
2009-08-17 | Name : Fedora Core 11 FEDORA-2009-8177 (Django) File : nvt/fcore_2009_8177.nasl |
2009-08-11 | Name : Django Directory Traversal Vulnerability (Linux) File : nvt/gb_django_dir_traversal_vuln_lin.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
58832 | Django Forms Library Multiple Field RegEx Handling DoS Django contains a flaw that may allow a remote denial of service. The issue is triggered when a malicious user puts a specially crafted email address or URL in any of the fields in the form library, and will result in loss of availability for the platform. |
56790 | Django core/servers/basehttp.py Admin Media Handler Static Media File Travers... |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2010-02-24 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1905.nasl - Type : ACT_GATHER_INFO |
2009-10-19 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_87917d6fba7611debac2001a4d563a0f.nasl - Type : ACT_GATHER_INFO |
2009-10-15 | Name : The remote Mandriva Linux host is missing a security update. File : mandriva_MDVSA-2009-275.nasl - Type : ACT_GATHER_INFO |
2009-10-15 | Name : The remote Mandriva Linux host is missing a security update. File : mandriva_MDVSA-2009-276.nasl - Type : ACT_GATHER_INFO |
2009-08-04 | Name : The remote Fedora host is missing a security update. File : fedora_2009-8169.nasl - Type : ACT_GATHER_INFO |
2009-08-04 | Name : The remote Fedora host is missing a security update. File : fedora_2009-8177.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2017-08-17 09:25:21 |
|
2016-08-18 01:05:09 |
|
2016-04-26 22:27:45 |
|
2014-02-17 11:40:52 |
|
2013-05-11 00:47:46 |
|