Git-Url: 
http://git.frugalware.org/gitweb/gitweb.cgi?p=homepage-ng.git;a=commitdiff;h=3a4be859fbb79f0b922c11daa4bd96f8e458a982

commit 3a4be859fbb79f0b922c11daa4bd96f8e458a982
Author: voroskoi <[EMAIL PROTECTED]>
Date:   Fri Nov 2 11:04:24 2007 +0100

FSA313-django

diff --git a/frugalware/xml/security.xml b/frugalware/xml/security.xml
index fafdba9..d3a5c5a 100644
--- a/frugalware/xml/security.xml
+++ b/frugalware/xml/security.xml
@@ -27,6 +27,18 @@

<fsas>
<fsa>
+               <id>313</id>
+               <date>2007-11-02</date>
+               <author>voroskoi</author>
+               <package>django</package>
+               <vulnerable>0.96-1</vulnerable>
+               <unaffected>0.96-2sayshell1</unaffected>
+               <bts>http://bugs.frugalware.org/task/2543</bts>
+               
<cve>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5712</cve>
+               <desc>A vulnerability has been reported in Django, which 
potentially can be exploited by malicious people to cause a DoS (Denial of 
Service).
+                       The vulnerability is caused due to the Django 
internationalization system ("i18n") incorrectly processing HTTP headers. This 
can be exploited to allocate large amounts of memory by sending specially 
crafted HTTP "Accept-Language" requests. Successful exploitation requires that 
the "USE_I18N" option and the "i18n" middleware component are enabled.</desc>
+       </fsa>
+       <fsa>
<id>312</id>
<date>2007-11-02</date>
<author>voroskoi</author>
_______________________________________________
Frugalware-git mailing list
[email protected]
http://frugalware.org/mailman/listinfo/frugalware-git

Reply via email to