Git-Url: http://git.frugalware.org/gitweb/gitweb.cgi?p=homepage-ng.git;a=commitdiff;h=3a4be859fbb79f0b922c11daa4bd96f8e458a982
commit 3a4be859fbb79f0b922c11daa4bd96f8e458a982 Author: voroskoi <[EMAIL PROTECTED]> Date: Fri Nov 2 11:04:24 2007 +0100 FSA313-django diff --git a/frugalware/xml/security.xml b/frugalware/xml/security.xml index fafdba9..d3a5c5a 100644 --- a/frugalware/xml/security.xml +++ b/frugalware/xml/security.xml @@ -27,6 +27,18 @@ <fsas> <fsa> + <id>313</id> + <date>2007-11-02</date> + <author>voroskoi</author> + <package>django</package> + <vulnerable>0.96-1</vulnerable> + <unaffected>0.96-2sayshell1</unaffected> + <bts>http://bugs.frugalware.org/task/2543</bts> + <cve>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5712</cve> + <desc>A vulnerability has been reported in Django, which potentially can be exploited by malicious people to cause a DoS (Denial of Service). + The vulnerability is caused due to the Django internationalization system ("i18n") incorrectly processing HTTP headers. This can be exploited to allocate large amounts of memory by sending specially crafted HTTP "Accept-Language" requests. Successful exploitation requires that the "USE_I18N" option and the "i18n" middleware component are enabled.</desc> + </fsa> + <fsa> <id>312</id> <date>2007-11-02</date> <author>voroskoi</author> _______________________________________________ Frugalware-git mailing list [email protected] http://frugalware.org/mailman/listinfo/frugalware-git
