[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 4006-1] python-django security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4006-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                           Chris Lamb
December 31, 2024                             https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : python-django
Version        : 2:2.2.28-1~deb11u3
CVE ID         : CVE-2024-53907

It was discovered that there was a potential Denial of Service (DoS)
vulnerability, in Django, a popular Python-based web development
framework.

The strip_tags() method and striptags template filter were subject to
a potential denial-of-service attack via certain inputs containing
large sequences of nested incomplete HTML entities.

For Debian 11 bullseye, this problem has been fixed in version
2:2.2.28-1~deb11u3.

We recommend that you upgrade your python-django packages.

For the detailed security status of python-django please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/python-django

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmd0BmgACgkQHpU+J9Qx
HlhLFhAAwcroO4+AxOc6RTndU6qJgzxwvCmBcT7g8bynBfFKvEQ/0Ybmk2Y6hM6q
wU6493V1M/TjKEpzWuytsBo0lTMHqMuXvne/iTuNNNoru0GIvCO2NfkAQNvMtUiY
FKpWFUMoOx6ezbuvr/wWl4T94vuzZYJhajXoyDffCb6iEOdO3lbbbG0fEuuqkQq1
0BYrgocgmZ4HiwScDJhB3V5z+ulW4Dq5zq5so4Ul0BW/I36IIgCMUOgEfsH97ixE
3wlCH+gwujlOzG7ryGts6FP+IT5AzNVAvB4YyjsZ8ADoqMzx73XmRyjP7fu+VW8n
F8K8cqdJKhhNDUMhgemaqFdwdClHOwQlmnkM7hh5qqa3dPG/JLW4OqQxWHqaBOR4
0ECAPJe8HPtMBl4fTxGtJmykbKY803pjaBejqlaQtFL/Z7fklJCrQPQgEfNlk3jm
mgoGmN1MuX98h4BntR3erbMhbTHn2pYYMvIPZS/xvd4Q17+ev3Gzaxu7SlrtSSLr
r2UrInpt3skigymS015rMuHxtpmbX7BAU4wmHWZLhPkZ3Fj1BFFlTLZsV5rtjtRM
N5rDevzX9Nx/5qVie4ye/UNrypEagFjgdxpUw15VWLmokMZqAQ1/KLdc+Mn0cthx
gg6zoKuUDMHAzkKSl6KfzlIw+s55rKHkqh199cNV2AtQgwSNaGs=
=vf8E
-----END PGP SIGNATURE-----


Reply to: