Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2013.1303 python-django security update 18 September 2013 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: python-django Publisher: Debian Operating System: Debian GNU/Linux 6 Debian GNU/Linux 7 UNIX variants (UNIX, Linux, OSX) Windows Impact/Access: Denial of Service -- Remote/Unauthenticated Resolution: Patch/Upgrade CVE Names: CVE-2013-1443 Original Bulletin: http://www.debian.org/security/2013/dsa-2758 Comment: This advisory references vulnerabilities in products which run on platforms other than Debian. It is recommended that administrators running python-django check for an updated version of the software for their operating system. - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - - ------------------------------------------------------------------------- Debian Security Advisory DSA-2758-1 security@debian.org http://www.debian.org/security/ Salvatore Bonaccorso September 17, 2013 http://www.debian.org/security/faq - - ------------------------------------------------------------------------- Package : python-django Vulnerability : denial of service Problem type : remote Debian-specific: no CVE ID : CVE-2013-1443 Debian Bug : 723043 It was discovered that python-django, a high-level Python web develompent framework, is prone to a denial of service vulnerability via large passwords. A non-authenticated remote attacker could mount a denial of service by submitting arbitrarily large passwords, tying up server resources in the expensive computation of the corresponding hashes to verify the password. For the oldstable distribution (squeeze), this problem has been fixed in version 1.2.3-3+squeeze8. For the stable distribution (wheezy), this problem has been fixed in version 1.4.5-1+deb7u4. For the unstable distribution (sid), this problem has been fixed in version 1.5.4-1. We recommend that you upgrade your python-django packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org - -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.14 (GNU/Linux) iQIcBAEBCgAGBQJSOJ/pAAoJEHidbwV/2GP+G1sP/RjyId0sDXuCUkDdkMyVS31+ 5Hn5Gi5k9KtSAXD6hvVg8kvBWDJRonVUXuJ4cA2YwLtf8sdS7cI0SW/9w1xujnFS TGvh2+Ghs8mxEeWj8pkHRUcoUdO985Z23GbSHYehC9JARZ0mFxLXCHwdJ8d1gLK3 7ZeV94KFx6z4dAA2zXZ3C87NN8ZTtiZfBeG1kvj+EnDMeOr2o72HgQShrLLONmBw 3s37LVgXNyoQyWt1Dt00axKfahe1eBdZd3Ex5iDfhciWgLgRmkmjFK+FgI4DwOHU B4QY4dUhv+t4LX24IQuk3g/1omxpDZR/CXJaZ7Sdm3Xc2dbgqnQohExa5Dw7bwZ/ iGhQmfMPpUxSzYw2dSsygbBbxfRq2aVvxb7iFf2XJMXdQrrt7rVtqDR28HTdfFZ8 SLrzHlGSfcRqf+vlq3UqDCxjd+OHewFej6ZOmRYWV6vK4Uh9pmFmrPLJHg4EdDlr 67ZnvHVguF0YdpP3hi8N5pN5nNGUCwyt/lJxiDu6fESvIM/l/joa6MXVpEIb7Ej/ 4ncefHu5fHLRlevKhOtu6SRvEUKAKZK7VZfdrC59S0r+AkNmRhO/XXM9Utm+8eLo 1zoufD+JS2S6ReNq/5K4TQHS+cy2qbBE6PtecDcVwiF4xrb9PJzd2fYUZ3dLdTkj e/HUma7XNVNT3NvkHnnq =OcAM - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: http://www.auscert.org.au/render.html?cid=1980 =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBUjkHMxLndAQH1ShLAQIC2w/+KaxyoBt31sHV89QO3pcQUJJ24VITF4iT X6pysAWs0oXGM8jN9Z2HTp4BTm93B6Kx4RS6TA/AO7ICMEzJynAlwjPR4GMVblSn jV6NEiLfkldKE6S99t6F5innGrubp4N6UtbAa/kcosfFMvyrfBV5YP0YJrrw+Iha fW6+h9+/aUDa2pvZHcavrH2jte4DqtyS7Z3Fc4x7+pQmHXeeSoDCroKge94EbOIl +E1aahSVzDbU1unTmOkxXYJeVcxFFBIxYMYJ/PXR2YPa+GHoloCjzBll8VnhMRUt NWTnsObn3Zqa21bjrBymM9u+F5fO4ZFA+YDnAL8012Bs7YDGkr05m9n6V5LlhRhB mfc2DL59ghn+zek4xFvPB/EYXOOsQ9b13+A9CzTbjZrGWQ2v2A/8cSvGjNJpTeZ/ dtrJhTe+Ch9TeBBPWhrTHJakpoqxX1PJlzOODRzCmqlgQJ5+nBgGI9+4dkxFZSPM FExe4Aeo/osw10UsWeUyU5ca+c+Ehm5XwJIJ7mIaf3QUX6Z9OK17T9adcBSADpAb rkFouRJ6YGiRc4tSrSv7Pz8irsoHr4+jKoyTtEY9JSilyy5AahgVnY+8Rwc9LAK5 BCJAIq1dYAyf44FVeIu0NxKXDE989P0lMqYr2UDXpWMftEQo5UVovxUvr4b3jdq3 40yteqjsrko= =2dHz -----END PGP SIGNATURE-----