You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa python-django

Sigurnosni nedostatak programskog paketa python-django

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-3851-1
January 09, 2019

python-django vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 18.10
– Ubuntu 18.04 LTS
– Ubuntu 16.04 LTS
– Ubuntu 14.04 LTS

Summary:

Django could be made to expose spoofed information over the network.

Software Description:
– python-django: High-level Python web development framework

Details:

It was discovered that Django incorrectly handled the default 404 page. A
remote attacker could use this issue to spoof content using a malicious
URL.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.10:
python-django 1:1.11.15-1ubuntu1.1
python3-django 1:1.11.15-1ubuntu1.1

Ubuntu 18.04 LTS:
python-django 1:1.11.11-1ubuntu1.2
python3-django 1:1.11.11-1ubuntu1.2

Ubuntu 16.04 LTS:
python-django 1.8.7-1ubuntu5.7
python3-django 1.8.7-1ubuntu5.7

Ubuntu 14.04 LTS:
python-django 1.6.11-0ubuntu1.3

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/usn/usn-3851-1
CVE-2019-3498

Package Information:
https://launchpad.net/ubuntu/+source/python-django/1:1.11.15-1ubuntu1.1
https://launchpad.net/ubuntu/+source/python-django/1:1.11.11-1ubuntu1.2
https://launchpad.net/ubuntu/+source/python-django/1.8.7-1ubuntu5.7
https://launchpad.net/ubuntu/+source/python-django/1.6.11-0ubuntu1.3

—–BEGIN PGP SIGNATURE—–

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAlw2R6YACgkQZWnYVadE
vpNp0w//RdO/FxHs+HMr7kctISPTsWTt/mY0YbEFXNtfdjrPoOfwLkQvOZ7/y3tZ
BzhU5zCeX+E5MjdxvexCSR7SLlTtG6SIcWa3orKlSiwCz1vUv/ASLc76nGwxHWas
B1xslQiZ3WeIthpv070pB+HKuyaJNOK/Q3q+cucLHJNWITKnKrAVKTUVdewL6p6M
cAxBfwJcsgaLMZKTfkKBoSALEfyxjtoecg34hJQal6OIRtrI8lhfa2W0RYEJMdG5
4pkCEvJ0zpIs9zTUlbSCGGEGfsy4KbtmNprp5sggI9dMRkOSSorsJ8wrh+HifUhS
ZY/9RCvQrrVUvV7tSI6Q/qLfTEjJJmQdWnqS3MuckL518RufgO5IqUd8cihOpRq5
WM0xHetMy3ggC6mhdwYGBErygi5wRr2AC9Ci870sFUAhJ2yU7O3N5otj16RpqrG2
FoI30K1uRV/k2XgpeCatOG6Wqopf4aN/g2asPGv7RqDzq/DnDLFgsFTZBbsWjkmt
UNAfdWDTLwTvw5vNU1L6PY1RODuEMuZYKW0TdCNAnUoWyzQtcjEXsFZl/qEDACGY
0teR2YYER981gu4s0eXVXClSpj5bQuzjgHmrqz4xARhO9yWxmIvZ7htBvcLUMJB1
QTZHvpe3ve4RCp6yQc7YI8UQQNMc5zblBOcgTngoQWliOkWXYWE=
=PX5v
—–END PGP SIGNATURE—–

AutorZvonimir Bosnjak
Cert idNCERT-REF-2019-01-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Nadogradnja za Microsoft Visual Studio

Microsoft je izdao nadogradnju za otklanjanje ranjivosti u Microsoft Visual Studio komponenti. Potencijalni napadači ranjivosti mogu iskoristiti za otkrivanje osjetljivih...

Close