Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.704161
Kategorie:Debian Local Security Checks
Titel:Debian Security Advisory DSA 4161-1 (python-django - security update)
Zusammenfassung:James Davis discovered two issues in Django, a high-level Python web;development framework, that can lead to a denial-of-service attack.;An attacker with control on the input of the django.utils.html.urlize();function or django.utils.text.Truncator's chars() and words() methods;could craft a string that might stuck the execution of the application.
Beschreibung:Summary:
James Davis discovered two issues in Django, a high-level Python web
development framework, that can lead to a denial-of-service attack.
An attacker with control on the input of the django.utils.html.urlize()
function or django.utils.text.Truncator's chars() and words() methods
could craft a string that might stuck the execution of the application.

Affected Software/OS:
python-django on Debian Linux

Solution:
For the oldstable distribution (jessie), these problems have been fixed
in version 1.7.11-1+deb8u3.

For the stable distribution (stretch), these problems have been fixed in
version 1:1.10.7-2+deb9u1.

We recommend that you upgrade your python-django packages.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2018-7536
BugTraq ID: 103361
http://www.securityfocus.com/bid/103361
Debian Security Information: DSA-4161 (Google Search)
https://www.debian.org/security/2018/dsa-4161
https://lists.debian.org/debian-lts-announce/2018/03/msg00006.html
RedHat Security Advisories: RHSA-2018:2927
https://access.redhat.com/errata/RHSA-2018:2927
RedHat Security Advisories: RHSA-2019:0051
https://access.redhat.com/errata/RHSA-2019:0051
RedHat Security Advisories: RHSA-2019:0082
https://access.redhat.com/errata/RHSA-2019:0082
RedHat Security Advisories: RHSA-2019:0265
https://access.redhat.com/errata/RHSA-2019:0265
https://usn.ubuntu.com/3591-1/
Common Vulnerability Exposure (CVE) ID: CVE-2018-7537
BugTraq ID: 103357
http://www.securityfocus.com/bid/103357
CopyrightCopyright (C) 2018 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.