Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 162818
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Executioner <keith@email.arizona.edu>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 162818 depends on: Show dependency tree
Bug 162818 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-01-19 15:44 0000
Description:
Some vulnerabilities have been reported in Django, which can be exploited by
malicious users to bypass certain security restrictions or malicious people to
compromise a vulnerable system.

1) The bin/compile-messages.py script does not correctly escape the filename of
.po message files. This can be exploited to execute arbitrary shell commands
via a maliciously named .po file.

2) The authentication middleware incorrectly caches the "request.user"
parameter between requests, which could be exploited to e.g. access pages as
another user.

The vulnerabilities are reported in version 0.95. Other versions may also be
affected.

Solution:
Fixed in the SVN repository.

http://code.djangoproject.com/changeset/3592
http://code.djangoproject.com/changeset/3754

Reproducible: Didn't try




http://code.djangoproject.com/ticket/2702
http://code.djangoproject.com/changeset/3592
http://code.djangoproject.com/changeset/3754

------- Comment #1 From Tiziano Müller 2007-01-21 13:44:18 0000 -------
Fixed with the revision bump from 0.95 to 0.95-r1: Patches from Debian added as
stated in the Changelog.
Thanks for reporting!

------- Comment #2 From Seemant Kulleen (RETIRED) 2007-01-22 09:12:59 0000 -------
Django upstream released 0.95.1 and I've added that into portage as well.

------- Comment #3 From Matthias Geerdsen 2007-01-22 20:14:56 0000 -------
closing without GLSA/stable marking, since django has not been marked stable on
any arch

thanks Tiziano/Seemant

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug