Login
Newsletter
Werbung

Sicherheit: Preisgabe von Informationen in Django
Aktuelle Meldungen Distributionen
Name: Preisgabe von Informationen in Django
ID: USN-2816-1
Distribution: Ubuntu
Plattformen: Ubuntu 12.04 LTS, Ubuntu 14.04 LTS, Ubuntu 15.04, Ubuntu 15.10
Datum: Di, 24. November 2015, 23:26
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8213
Applikationen: Django

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============0708541885933593683==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="hB9x94C6s0O6KS7xOTaBn89gR3gl29seT"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--hB9x94C6s0O6KS7xOTaBn89gR3gl29seT
Content-Type: text/plain; charset=utf-
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-2816-1
November 24, 2015

python-django vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10
- Ubuntu 15.04
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

Django could be made to expose sensitive information over the network.

Software Description:
- python-django: High-level Python web development framework

Details:

Ryan Butterfield discovered that Django incorrectly handled the date
template filter. A remote attacker could possibly use this issue to obtain
secrets from application settings.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
python-django 1.7.9-1ubuntu5.1
python3-django 1.7.9-1ubuntu5.1

Ubuntu 15.04:
python-django 1.7.6-1ubuntu2.3
python3-django 1.7.6-1ubuntu2.3

Ubuntu 14.04 LTS:
python-django 1.6.1-2ubuntu0.11

Ubuntu 12.04 LTS:
python-django 1.3.1-4ubuntu1.19

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2816-1
CVE-2015-8213

Package Information:
https://launchpad.net/ubuntu/+source/python-django/1.7.9-1ubuntu5.1
https://launchpad.net/ubuntu/+source/python-django/1.7.6-1ubuntu2.3
https://launchpad.net/ubuntu/+source/python-django/1.6.1-2ubuntu0.11
https://launchpad.net/ubuntu/+source/python-django/1.3.1-4ubuntu1.19



--hB9x94C6s0O6KS7xOTaBn89gR3gl29seT
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJWVLDuAAoJEGVp2FWnRL6T+lUP/1uierDypzxhQ1q5nEjCGCFu
r8hBQq7zGnYGhfniqzYrtbpX0uI38o31Wlws+t7bclY/txtrYDcm+wCsYSQga99o
3D2upRFROjJnsPSscOa6cRIS7WhlRh6L/kaUzdhmYDwbx+Nf0sWUGU8Y2+Tj6llI
u/ZpJLWMKumsteBNS5XWFR1c2pRsa7rYDmXzKn526TKjsAAbi+QdMmCsST9ckUb6
aghnyKRyhAJsm2T4nQIMkYUuU8VeKV+ad4MHKwWnXXN8nO+nkOB8Po3AJBAMgCP1
96FGCy75yRNO7MXaJqtx7A+c13GJBds9mz7LUoYnZ4ZagpQl4q/3UDpE/C6dQwqS
d1J16s2Hd4pP2KVisGab+APrDLRrvF1W6r0FaD5Qrl8dKKvbXGbz+1FVzhDRv1pL
QJyToV9ZOp52QiWHdwdydxERYXD7mzLw/BTDY5NeYLH7ukaI32rSm/FyiGWqTHls
lm/TFsziLi44Tky6BZ28WMFN/Cm3HD6/RVVimRQJHrDcK5e/DYUl7um+7OLDffRI
7tVNPqW7XYCXETKPcxpccZBSn3gC7rHHAPLesuX1kaBzvCbyqbBk7OK5AO9h9dIq
bwpeW2ZndD6CIVDVkXxJVLhSGKH8ubyCWbXGf/2yCz2FefH1RljM4aAEkp2AKbgE
shlpYznwZxb7rLufTYEy
=356I
-----END PGP SIGNATURE-----

--hB9x94C6s0O6KS7xOTaBn89gR3gl29seT--


--===============0708541885933593683==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============0708541885933593683==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung