python-django 2:3.2.11-1 source package in Ubuntu

Changelog

python-django (2:3.2.11-1) unstable; urgency=high

  * New upstream security release:

    - CVE-2021-45115: Denial-of-service possibility in
      UserAttributeSimilarityValidator

      UserAttributeSimilarityValidator incurred significant overhead evaluating
      submitted password that were artificially large in relative to the
      comparison values. On the assumption that access to user registration was
      unrestricted this provided a potential vector for a denial-of-service
      attack.

      In order to mitigate this issue, relatively long values are now ignored
      by UserAttributeSimilarityValidator.

    - CVE-2021-45116: Potential information disclosure in dictsort template
      filter

      Due to leveraging the Django Template Language's variable resolution
      logic, the dictsort template filter was potentially vulnerable to
      information disclosure or unintended method calls, if passed a
      suitably crafted key.

      In order to avoid this possibility, dictsort now works with a
      restricted resolution logic, that will not call methods, nor allow
      indexing on dictionaries.

    - CVE-2021-45452: Potential directory-traversal via Storage.save()

      Storage.save() allowed directory-traversal if directly passed suitably
      crafted file names.

    See <https://www.djangoproject.com/weblog/2022/jan/04/security-releases/>
    for more information. (Closes: #1003113)

 -- Chris Lamb <email address hidden>  Tue, 04 Jan 2022 12:35:16 +0000

Upload details

Uploaded by:
Debian Python Team
Uploaded to:
Sid
Original maintainer:
Debian Python Team
Architectures:
all
Section:
python
Urgency:
Very Urgent

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Jammy: [FAILEDTOBUILD] amd64

Downloads

File Size SHA-256 Checksum
python-django_3.2.11-1.dsc 2.7 KiB 4fc271234dfa156b49b4f7cac8f47388c3dd35c7ccb152c1a5453e7490cf530b
python-django_3.2.11.orig.tar.gz 9.4 MiB 69c94abe5d6b1b088bf475e09b7b74403f943e34da107e798465d2045da27e75
python-django_3.2.11-1.debian.tar.xz 33.4 KiB 0a54468ae6869cfbe15f4770818fcf1c0f59dce3299390707346a9148537a6f2

Available diffs

No changes file available.

Binary packages built by this source