-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2013.1303
                       python-django security update
                             18 September 2013

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           python-django
Publisher:         Debian
Operating System:  Debian GNU/Linux 6
                   Debian GNU/Linux 7
                   UNIX variants (UNIX, Linux, OSX)
                   Windows
Impact/Access:     Denial of Service -- Remote/Unauthenticated
Resolution:        Patch/Upgrade
CVE Names:         CVE-2013-1443  

Original Bulletin: 
   http://www.debian.org/security/2013/dsa-2758

Comment: This advisory references vulnerabilities in products which run on 
         platforms other than Debian. It is recommended that administrators 
         running python-django check for an updated version of the software 
         for their operating system.

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- - -------------------------------------------------------------------------
Debian Security Advisory DSA-2758-1                   security@debian.org
http://www.debian.org/security/                      Salvatore Bonaccorso
September 17, 2013                     http://www.debian.org/security/faq
- - -------------------------------------------------------------------------

Package        : python-django
Vulnerability  : denial of service
Problem type   : remote
Debian-specific: no
CVE ID         : CVE-2013-1443
Debian Bug     : 723043

It was discovered that python-django, a high-level Python web
develompent framework, is prone to a denial of service vulnerability
via large passwords.

A non-authenticated remote attacker could mount a denial of service by
submitting arbitrarily large passwords, tying up server resources in
the expensive computation of the corresponding hashes to verify the
password.

For the oldstable distribution (squeeze), this problem has been fixed in
version 1.2.3-3+squeeze8.

For the stable distribution (wheezy), this problem has been fixed in
version 1.4.5-1+deb7u4.

For the unstable distribution (sid), this problem has been fixed in
version 1.5.4-1.

We recommend that you upgrade your python-django packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)

iQIcBAEBCgAGBQJSOJ/pAAoJEHidbwV/2GP+G1sP/RjyId0sDXuCUkDdkMyVS31+
5Hn5Gi5k9KtSAXD6hvVg8kvBWDJRonVUXuJ4cA2YwLtf8sdS7cI0SW/9w1xujnFS
TGvh2+Ghs8mxEeWj8pkHRUcoUdO985Z23GbSHYehC9JARZ0mFxLXCHwdJ8d1gLK3
7ZeV94KFx6z4dAA2zXZ3C87NN8ZTtiZfBeG1kvj+EnDMeOr2o72HgQShrLLONmBw
3s37LVgXNyoQyWt1Dt00axKfahe1eBdZd3Ex5iDfhciWgLgRmkmjFK+FgI4DwOHU
B4QY4dUhv+t4LX24IQuk3g/1omxpDZR/CXJaZ7Sdm3Xc2dbgqnQohExa5Dw7bwZ/
iGhQmfMPpUxSzYw2dSsygbBbxfRq2aVvxb7iFf2XJMXdQrrt7rVtqDR28HTdfFZ8
SLrzHlGSfcRqf+vlq3UqDCxjd+OHewFej6ZOmRYWV6vK4Uh9pmFmrPLJHg4EdDlr
67ZnvHVguF0YdpP3hi8N5pN5nNGUCwyt/lJxiDu6fESvIM/l/joa6MXVpEIb7Ej/
4ncefHu5fHLRlevKhOtu6SRvEUKAKZK7VZfdrC59S0r+AkNmRhO/XXM9Utm+8eLo
1zoufD+JS2S6ReNq/5K4TQHS+cy2qbBE6PtecDcVwiF4xrb9PJzd2fYUZ3dLdTkj
e/HUma7XNVNT3NvkHnnq
=OcAM
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBUjkHMxLndAQH1ShLAQIC2w/+KaxyoBt31sHV89QO3pcQUJJ24VITF4iT
X6pysAWs0oXGM8jN9Z2HTp4BTm93B6Kx4RS6TA/AO7ICMEzJynAlwjPR4GMVblSn
jV6NEiLfkldKE6S99t6F5innGrubp4N6UtbAa/kcosfFMvyrfBV5YP0YJrrw+Iha
fW6+h9+/aUDa2pvZHcavrH2jte4DqtyS7Z3Fc4x7+pQmHXeeSoDCroKge94EbOIl
+E1aahSVzDbU1unTmOkxXYJeVcxFFBIxYMYJ/PXR2YPa+GHoloCjzBll8VnhMRUt
NWTnsObn3Zqa21bjrBymM9u+F5fO4ZFA+YDnAL8012Bs7YDGkr05m9n6V5LlhRhB
mfc2DL59ghn+zek4xFvPB/EYXOOsQ9b13+A9CzTbjZrGWQ2v2A/8cSvGjNJpTeZ/
dtrJhTe+Ch9TeBBPWhrTHJakpoqxX1PJlzOODRzCmqlgQJ5+nBgGI9+4dkxFZSPM
FExe4Aeo/osw10UsWeUyU5ca+c+Ehm5XwJIJ7mIaf3QUX6Z9OK17T9adcBSADpAb
rkFouRJ6YGiRc4tSrSv7Pz8irsoHr4+jKoyTtEY9JSilyy5AahgVnY+8Rwc9LAK5
BCJAIq1dYAyf44FVeIu0NxKXDE989P0lMqYr2UDXpWMftEQo5UVovxUvr4b3jdq3
40yteqjsrko=
=2dHz
-----END PGP SIGNATURE-----