You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa python-django

Sigurnosni nedostatak programskog paketa python-django

==========================================================================
Ubuntu Security Notice USN-2816-1
November 24, 2015

python-django vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 15.10
– Ubuntu 15.04
– Ubuntu 14.04 LTS
– Ubuntu 12.04 LTS

Summary:

Django could be made to expose sensitive information over the network.

Software Description:
– python-django: High-level Python web development framework

Details:

Ryan Butterfield discovered that Django incorrectly handled the date
template filter. A remote attacker could possibly use this issue to obtain
secrets from application settings.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
python-django 1.7.9-1ubuntu5.1
python3-django 1.7.9-1ubuntu5.1

Ubuntu 15.04:
python-django 1.7.6-1ubuntu2.3
python3-django 1.7.6-1ubuntu2.3

Ubuntu 14.04 LTS:
python-django 1.6.1-2ubuntu0.11

Ubuntu 12.04 LTS:
python-django 1.3.1-4ubuntu1.19

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2816-1
CVE-2015-8213

Package Information:
https://launchpad.net/ubuntu/+source/python-django/1.7.9-1ubuntu5.1
https://launchpad.net/ubuntu/+source/python-django/1.7.6-1ubuntu2.3
https://launchpad.net/ubuntu/+source/python-django/1.6.1-2ubuntu0.11
https://launchpad.net/ubuntu/+source/python-django/1.3.1-4ubuntu1.19

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2

iQIcBAEBCgAGBQJWVLDuAAoJEGVp2FWnRL6T+lUP/1uierDypzxhQ1q5nEjCGCFu
r8hBQq7zGnYGhfniqzYrtbpX0uI38o31Wlws+t7bclY/txtrYDcm+wCsYSQga99o
3D2upRFROjJnsPSscOa6cRIS7WhlRh6L/kaUzdhmYDwbx+Nf0sWUGU8Y2+Tj6llI
u/ZpJLWMKumsteBNS5XWFR1c2pRsa7rYDmXzKn526TKjsAAbi+QdMmCsST9ckUb6
aghnyKRyhAJsm2T4nQIMkYUuU8VeKV+ad4MHKwWnXXN8nO+nkOB8Po3AJBAMgCP1
96FGCy75yRNO7MXaJqtx7A+c13GJBds9mz7LUoYnZ4ZagpQl4q/3UDpE/C6dQwqS
d1J16s2Hd4pP2KVisGab+APrDLRrvF1W6r0FaD5Qrl8dKKvbXGbz+1FVzhDRv1pL
QJyToV9ZOp52QiWHdwdydxERYXD7mzLw/BTDY5NeYLH7ukaI32rSm/FyiGWqTHls
lm/TFsziLi44Tky6BZ28WMFN/Cm3HD6/RVVimRQJHrDcK5e/DYUl7um+7OLDffRI
7tVNPqW7XYCXETKPcxpccZBSn3gC7rHHAPLesuX1kaBzvCbyqbBk7OK5AO9h9dIq
bwpeW2ZndD6CIVDVkXxJVLhSGKH8ubyCWbXGf/2yCz2FefH1RljM4aAEkp2AKbgE
shlpYznwZxb7rLufTYEy
=356I
—–END PGP SIGNATURE—–

Top
More in Preporuke
Sigurnosni nedostaci programskog paketa libpng10

Otkriveni su sigurnosni nedostaci u programskom paketu libpng10 za operacijski sustav Fedora. Otkriveni nedostaci potencijalnim napadačima omogućuju otkrivanje informacija iz...

Close