drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Preisgabe von Informationen in Django
Name: |
Preisgabe von Informationen in Django |
|
ID: |
USN-2816-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 12.04 LTS, Ubuntu 14.04 LTS, Ubuntu 15.04, Ubuntu 15.10 |
|
Datum: |
Di, 24. November 2015, 23:26 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8213 |
|
Applikationen: |
Django |
|
Originalnachricht |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============0708541885933593683== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="hB9x94C6s0O6KS7xOTaBn89gR3gl29seT"
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --hB9x94C6s0O6KS7xOTaBn89gR3gl29seT Content-Type: text/plain; charset=utf- Content-Transfer-Encoding: quoted-printable
========================================================================== Ubuntu Security Notice USN-2816-1 November 24, 2015
python-django vulnerability ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 15.10 - Ubuntu 15.04 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS
Summary:
Django could be made to expose sensitive information over the network.
Software Description: - python-django: High-level Python web development framework
Details:
Ryan Butterfield discovered that Django incorrectly handled the date template filter. A remote attacker could possibly use this issue to obtain secrets from application settings.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 15.10: python-django 1.7.9-1ubuntu5.1 python3-django 1.7.9-1ubuntu5.1
Ubuntu 15.04: python-django 1.7.6-1ubuntu2.3 python3-django 1.7.6-1ubuntu2.3
Ubuntu 14.04 LTS: python-django 1.6.1-2ubuntu0.11
Ubuntu 12.04 LTS: python-django 1.3.1-4ubuntu1.19
In general, a standard system update will make all the necessary changes.
References: http://www.ubuntu.com/usn/usn-2816-1 CVE-2015-8213
Package Information: https://launchpad.net/ubuntu/+source/python-django/1.7.9-1ubuntu5.1 https://launchpad.net/ubuntu/+source/python-django/1.7.6-1ubuntu2.3 https://launchpad.net/ubuntu/+source/python-django/1.6.1-2ubuntu0.11 https://launchpad.net/ubuntu/+source/python-django/1.3.1-4ubuntu1.19
--hB9x94C6s0O6KS7xOTaBn89gR3gl29seT Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc"
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2
iQIcBAEBCgAGBQJWVLDuAAoJEGVp2FWnRL6T+lUP/1uierDypzxhQ1q5nEjCGCFu r8hBQq7zGnYGhfniqzYrtbpX0uI38o31Wlws+t7bclY/txtrYDcm+wCsYSQga99o 3D2upRFROjJnsPSscOa6cRIS7WhlRh6L/kaUzdhmYDwbx+Nf0sWUGU8Y2+Tj6llI u/ZpJLWMKumsteBNS5XWFR1c2pRsa7rYDmXzKn526TKjsAAbi+QdMmCsST9ckUb6 aghnyKRyhAJsm2T4nQIMkYUuU8VeKV+ad4MHKwWnXXN8nO+nkOB8Po3AJBAMgCP1 96FGCy75yRNO7MXaJqtx7A+c13GJBds9mz7LUoYnZ4ZagpQl4q/3UDpE/C6dQwqS d1J16s2Hd4pP2KVisGab+APrDLRrvF1W6r0FaD5Qrl8dKKvbXGbz+1FVzhDRv1pL QJyToV9ZOp52QiWHdwdydxERYXD7mzLw/BTDY5NeYLH7ukaI32rSm/FyiGWqTHls lm/TFsziLi44Tky6BZ28WMFN/Cm3HD6/RVVimRQJHrDcK5e/DYUl7um+7OLDffRI 7tVNPqW7XYCXETKPcxpccZBSn3gC7rHHAPLesuX1kaBzvCbyqbBk7OK5AO9h9dIq bwpeW2ZndD6CIVDVkXxJVLhSGKH8ubyCWbXGf/2yCz2FefH1RljM4aAEkp2AKbgE shlpYznwZxb7rLufTYEy =356I -----END PGP SIGNATURE-----
--hB9x94C6s0O6KS7xOTaBn89gR3gl29seT--
--===============0708541885933593683== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
--===============0708541885933593683==--
|
|
|
|