SUSE-SU-2015:1112-1

Source
https://www.suse.com/support/update/announcement/2015/suse-su-20151112-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:1112-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2015:1112-1
Related
Published
2015-03-30T09:04:33Z
Modified
2015-03-30T09:04:33Z
Summary
Security update for python-Django
Details

python-django was updated to 1.6.11 to fix security issues and non-security bugs.

The following vulnerabilities were fixed:

  • Made issafeurl() reject URLs that start with control characters to mitigate possible XSS attack via user-supplied redirect URLs (bnc#923176, CVE-2015-2317)
  • Fixed an infinite loop possibility in strip_tags() (bnc#923172, CVE-2015-2316)
  • WSGI header spoofing via underscore/dash conflation (bnc#913053, CVE-2015-0219)
  • Mitigated possible XSS attack via user-supplied redirect URLs
  • Denial-of-service attack against django.views.static.serve (bnc#913056, CVE-2015-0221)
  • Database denial-of-service with ModelMultipleChoiceField (bnc#913055, CVE-2015-0222)

The update also contains fixes for non-security bugs, functional and stability issues.

References

Affected packages

SUSE:Enterprise Storage 1.0 / python-Django

Package

Name
python-Django
Purl
purl:rpm/suse/python-Django&distro=SUSE%20Enterprise%20Storage%201.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.11-4.1

Ecosystem specific

{
    "binaries": [
        {
            "python-Django": "1.6.11-4.1"
        }
    ]
}