-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 _______________________________________________________________________ Mandriva Linux Security Advisory MDVSA-2015:036 http://www.mandriva.com/en/support/security/ _______________________________________________________________________ Package : python-django Date : February 6, 2015 Affected: Business Server 1.0 _______________________________________________________________________ Problem Description: Updated python-django packages fix security vulnerabilities: Jedediah Smith discovered that Django incorrectly handled underscores in WSGI headers. A remote attacker could possibly use this issue to spoof headers in certain environments (CVE-2015-0219). Mikko Ohtamaa discovered that Django incorrectly handled user-supplied redirect URLs. A remote attacker could possibly use this issue to perform a cross-site scripting attack (CVE-2015-0220). Alex Gaynor discovered that Django incorrectly handled reading files in django.views.static.serve(). A remote attacker could possibly use this issue to cause Django to consume resources, resulting in a denial of service (CVE-2015-0221). _______________________________________________________________________ References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0219 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0220 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0221 http://advisories.mageia.org/MGASA-2015-0026.html http://www.ubuntu.com/usn/usn-2469-1/ _______________________________________________________________________ Updated Packages: Mandriva Business Server 1/X86_64: 6aca823622d72f52dd8cfa51ef4c29ed mbs1/x86_64/python-django-1.3.7-1.7.mbs1.noarch.rpm d808bb116f807286495653b08605380d mbs1/SRPMS/python-django-1.3.7-1.7.mbs1.src.rpm _______________________________________________________________________ To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you. All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing: gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98 You can view other update advisories for Mandriva Linux at: http://www.mandriva.com/en/support/security/advisories/ If you want to report vulnerabilities, please contact security_(at)_mandriva.com _______________________________________________________________________ Type Bits/KeyID Date User ID pub 1024D/22458A98 2000-07-10 Mandriva Security Team -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iD8DBQFU1IsQmqjQ0CJFipgRAsdUAJ9saL1ewdIH+iaIQRVfb0jTMN1cPwCgn1ta KgsRxKZUikRv0qtXtKb3sA0= =r1sB -----END PGP SIGNATURE-----