==========================================================================
Ubuntu Security Notice USN-3851-1
January 09, 2019
python-django vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 18.10
– Ubuntu 18.04 LTS
– Ubuntu 16.04 LTS
– Ubuntu 14.04 LTS
Summary:
Django could be made to expose spoofed information over the network.
Software Description:
– python-django: High-level Python web development framework
Details:
It was discovered that Django incorrectly handled the default 404 page. A
remote attacker could use this issue to spoof content using a malicious
URL.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.10:
python-django 1:1.11.15-1ubuntu1.1
python3-django 1:1.11.15-1ubuntu1.1
Ubuntu 18.04 LTS:
python-django 1:1.11.11-1ubuntu1.2
python3-django 1:1.11.11-1ubuntu1.2
Ubuntu 16.04 LTS:
python-django 1.8.7-1ubuntu5.7
python3-django 1.8.7-1ubuntu5.7
Ubuntu 14.04 LTS:
python-django 1.6.11-0ubuntu1.3
In general, a standard system update will make all the necessary changes.
References:
https://usn.ubuntu.com/usn/usn-3851-1
CVE-2019-3498
Package Information:
https://launchpad.net/ubuntu/+source/python-django/1:1.11.15-1ubuntu1.1
https://launchpad.net/ubuntu/+source/python-django/1:1.11.11-1ubuntu1.2
https://launchpad.net/ubuntu/+source/python-django/1.8.7-1ubuntu5.7
https://launchpad.net/ubuntu/+source/python-django/1.6.11-0ubuntu1.3
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAlw2R6YACgkQZWnYVadE
vpNp0w//RdO/FxHs+HMr7kctISPTsWTt/mY0YbEFXNtfdjrPoOfwLkQvOZ7/y3tZ
BzhU5zCeX+E5MjdxvexCSR7SLlTtG6SIcWa3orKlSiwCz1vUv/ASLc76nGwxHWas
B1xslQiZ3WeIthpv070pB+HKuyaJNOK/Q3q+cucLHJNWITKnKrAVKTUVdewL6p6M
cAxBfwJcsgaLMZKTfkKBoSALEfyxjtoecg34hJQal6OIRtrI8lhfa2W0RYEJMdG5
4pkCEvJ0zpIs9zTUlbSCGGEGfsy4KbtmNprp5sggI9dMRkOSSorsJ8wrh+HifUhS
ZY/9RCvQrrVUvV7tSI6Q/qLfTEjJJmQdWnqS3MuckL518RufgO5IqUd8cihOpRq5
WM0xHetMy3ggC6mhdwYGBErygi5wRr2AC9Ci870sFUAhJ2yU7O3N5otj16RpqrG2
FoI30K1uRV/k2XgpeCatOG6Wqopf4aN/g2asPGv7RqDzq/DnDLFgsFTZBbsWjkmt
UNAfdWDTLwTvw5vNU1L6PY1RODuEMuZYKW0TdCNAnUoWyzQtcjEXsFZl/qEDACGY
0teR2YYER981gu4s0eXVXClSpj5bQuzjgHmrqz4xARhO9yWxmIvZ7htBvcLUMJB1
QTZHvpe3ve4RCp6yQc7YI8UQQNMc5zblBOcgTngoQWliOkWXYWE=
=PX5v
—–END PGP SIGNATURE—–
—