• Django vulnerabilities

    From bugz_ubuntu@21:4/110 to Ubuntu Users on Wednesday, June 03, 2020 08:10:01
    python-django vulnerabilities

    A security issue affects these releases of Ubuntu and its
    derivatives:

    * Ubuntu 20.04 LTS
    * Ubuntu 19.10
    * Ubuntu 18.04 LTS
    * Ubuntu 16.04 LTS

    Summary

    Several security issues were fixed in Django.

    Software Description

    * python-django - High-level Python web development framework

    Details

    Dan Palmer discovered that Django incorrectly validated memcached
    cache keys. A remote attacker could possibly use this issue to
    cause a denial of service and obtain sensitive information.
    (CVE-2020-13254)

    Jon Dufresne discovered that Django incorrectly encoded query
    parameters for the admin ForeignKeyRawIdWidget. A remote attacker
    could possibly use this issue to perform XSS attacks.
    (CVE-2020-13596)

    Update instructions

    The problem can be corrected by updating your system to the
    following package versions:

    Ubuntu 20.04 LTS
    python3-django - 2:2.2.12-1ubuntu0.1

    Ubuntu 19.10
    python-django - 1:1.11.22-1ubuntu1.4
    python3-django - 1:1.11.22-1ubuntu1.4

    Ubuntu 18.04 LTS
    python-django - 1:1.11.11-1ubuntu1.9
    python3-django - 1:1.11.11-1ubuntu1.9

    Ubuntu 16.04 LTS
    python-django - 1.8.7-1ubuntu5.13
    python3-django - 1.8.7-1ubuntu5.13

    To update your system, please follow these instructions:
    https://wiki.ubuntu.com/Security/Upgrades.

    In general, a standard system update will make all the necessary
    changes.

    References

    * CVE-2020-13254
    * CVE-2020-13596

    --- Mystic BBS v1.12 A45 (Linux/64)
    * Origin: BZ&BZ BBS (21:4/110)
  • From bugz_ubuntu@21:4/110 to Ubuntu Users on Thursday, June 04, 2020 12:10:02
    python-django vulnerabilities

    A security issue affects these releases of Ubuntu and its
    derivatives:

    * Ubuntu 14.04 ESM

    Summary

    Several security issues were fixed in Django.

    Software Description

    * python-django - High-level Python web development framework

    Details

    USN-4381-1 fixed several vulnerabilities in Django. This update
    provides the corresponding update for Ubuntu 14.04 ESM.

    Original advisory details:

    Dan Palmer discovered that Django incorrectly validated memcached
    cache keys. A remote attacker could possibly use this issue to
    cause a denial of service and obtain sensitive information.
    (CVE-2020-13254)

    Jon Dufresne discovered that Django incorrectly encoded query
    parameters for the admin ForeignKeyRawIdWidget. A remote attacker
    could possibly use this issue to perform XSS attacks.
    (CVE-2020-13596)

    Update instructions

    The problem can be corrected by updating your system to the
    following package versions:

    Ubuntu 14.04 ESM
    python-django - 1.6.11-0ubuntu1.3+esm1

    To update your system, please follow these instructions:
    https://wiki.ubuntu.com/Security/Upgrades.

    In general, a standard system update will make all the necessary
    changes.

    References

    * USN-4381-1
    * CVE-2020-13254
    * CVE-2020-13596

    --- Mystic BBS v1.12 A45 (Linux/64)
    * Origin: BZ&BZ BBS (21:4/110)
  • From bugz_ubuntu@21:4/110 to Ubuntu Users on Tuesday, September 01, 2020 12:10:02
    python-django vulnerabilities

    A security issue affects these releases of Ubuntu and its
    derivatives:

    * Ubuntu 20.04 LTS

    Summary

    Several security issues were fixed in Django.

    Software Description

    * python-django - High-level Python web development framework

    Details

    It was discovered that Django, when used with Python 3.7 or
    higher, incorrectly handled directory permissions. A local
    attacker could possibly use this issue to obtain sensitive
    information, or escalate permissions.

    Update instructions

    The problem can be corrected by updating your system to the
    following package versions:

    Ubuntu 20.04 LTS
    python3-django - 2:2.2.12-1ubuntu0.2

    To update your system, please follow these instructions:
    https://wiki.ubuntu.com/Security/Upgrades.

    In general, a standard system update will make all the necessary
    changes.

    References

    * CVE-2020-24583
    * CVE-2020-24584

    --- Mystic BBS v1.12 A46 (Linux/64)
    * Origin: BZ&BZ BBS (21:4/110)