[Bug 1227518] Re: CVE-2013-4315: Directory traversal with ssi template tag

2013-09-24 Thread Felix Dreissig
This was fixed in one go with #1225784. ** Changed in: python-django (Ubuntu) Status: Confirmed = Fix Released -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to python-django in Ubuntu. https://bugs.launchpad.net/bugs/1227518

[Bug 1227518] [NEW] CVE-2013-4315: Directory traversal with ssi template tag

2013-09-19 Thread Felix Dreissig
*** This bug is a security vulnerability *** Public security bug reported: Django's template language includes two methods of including and rendering one template inside another: The {% include %} tag takes a template name, and uses Django's template loading mechanism (which is restricted to