drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Cross-Site Scripting in Django
Name: |
Cross-Site Scripting in Django |
|
ID: |
USN-1004-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 10.10 |
|
Datum: |
Do, 14. Oktober 2010, 10:19 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3082 |
|
Applikationen: |
Django |
|
Originalnachricht |
--===============0374203859204192837== Content-Type: multipart/signed; micalg="pgp-sha1"; protocol="application/pgp-signature"; boundary="=-qhbiOX0KKjVoVC2H5BZO"
--=-qhbiOX0KKjVoVC2H5BZO Content-Type: text/plain; charset="UTF-8 Content-Transfer-Encoding: quoted-printable
=========================================================== Ubuntu Security Notice USN-1004-1 October 13, 2010 python-django vulnerability CVE-2010-3082 ===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 10.10
This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 10.10: python-django 1.2.3-1ubuntu0.1
In general, a standard system update will make all the necessary changes.
Details follow:
It was discovered that Django did not properly sanitize the cookie value when applying CSRF protections resulting in a cross-site scripting (XSS) vulnerability. With cross-site scripting vulnerabilities, if a user were tricked into viewing server output during a crafted server request, a remote attacker could exploit this to modify the contents, or steal confidential data, within the same domain.
Updated packages for Ubuntu 10.10:
Source archives:
python-django_1.2.3-1ubuntu0.1.debian.tar.gz Size/MD5: 18499 2e8c4c95d6d40cce184131f1001a01a2 python-django_1.2.3-1ubuntu0.1.dsc Size/MD5: 2249 a5cb861587d952430ae73da49a9680cf python-django_1.2.3.orig.tar.gz Size/MD5: 6306760 10bfb5831bcb4d3b1e6298d0e41d6603
Architecture independent packages:
python-django-doc_1.2.3-1ubuntu0.1_all.deb Size/MD5: 1905856 5f3ed62933c8f4970101ead2d57d7d4f python-django_1.2.3-1ubuntu0.1_all.deb Size/MD5: 4212250 8c85dcb4ab4d9701cd546e2e119ae4e3
--
|
|
|
|