You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa python-django

Sigurnosni nedostaci programskog paketa python-django

==========================================================================
Ubuntu Security Notice USN-3559-1
February 07, 2018

python-django vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 17.10

Summary:

Several security issues were fixed in Django.

Software Description:
– python-django: High-level Python web development framework

Details:

It was discovered that Django incorrectly handled certain requests.
An attacker could possibly use this to access sensitive information.
(CVE-2017-12794, CVE-2018-6188)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 17.10:
  python-django                   1:1.11.4-1ubuntu1.1
  python3-django                  1:1.11.4-1ubuntu1.1

In general, a standard system update will make all the necessary
changes.

References:
  https://www.ubuntu.com/usn/usn-3559-1
  CVE-2017-12794, CVE-2018-6188

Package Information:
  https://launchpad.net/ubuntu/+source/python-django/1:1.11.4-1ubuntu1.1
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2

iQIcBAABCAAGBQJaexBSAAoJEEW851uECx9pKuAP+gNrCAp8/IPWj9QVvFiIakbe
XmkhkZbYl4H/SEgA5RkC8O5g/ws+J7ziD5g0zbY/zoBZ3wml31lqNntLdBc1j0mM
Py6TCQA4DY9JjloUvjq6vPaMpxH76XjS3ylqf+/J6TAmUkiI0AbWSBrSAkmTLiYN
LQv/RsVBqaoe0pkqyVHJFv6y3BkxcSbcb5Lhrx9iYro49nvAa8BI5m9aLiHcmgHw
5b7MMXy/0jlRsVPhsC4nZ55Ty5OWW55u5XUmxb55g/uqZ53SDXb8HxwmemYHVCPD
ifFI6oDbbH5BTwpMpfDtySHGxaExO6kyn1YYatiCJ9C70OciK45NyjaEZkS4mnkM
OA7G0avFRpWEC46VM1RwyIdB8uYB9CnHPhJETC0DHpd6ilYOuHJ3/nnsf8Df/g+X
I3G7gCBKHFWaW7gEbd4MrkmJgLBkvX9aqyFvmVtKfzsJ+1aBmU00avZcg8Qw6PNO
h8TKVz+5vw+papvdNeIf8FQeWi8DkFCKIp8qD0Hb5niRjUMqiOOH1S52UTtf5W4E
+iq3DNCtfFfXFxnH47CzcWiWIuau16gHtTVrXlwPHJyamrfs1+sNpxanQST75RpR
F6FU+JOiytombI/xWLmlqI8f3w6SY8szQSd/dzF7spcRmGin79ht0mKwq5kn+F2I
r9jJUfr2uSznyxVTx50O
=BePn
—–END PGP SIGNATURE—–

Top
More in Preporuke
Sigurnosni nedostaci programskog paketa jackson-databind

Otkriveni su sigurnosni nedostaci u programskom paketu jackson-databind za operativni sustav Fedora. Otkriveni nedostaci potencijalnim udaljenim napadačima omogućuju izvršavanje proizvoljnog...

Close