Fedora 21 Security Update: python-django-1.6.10-1.fc21

Resolved Bugs
1181939 – CVE-2015-0219 python-django: Django: WSGI header spoofing via underscore/dash conflation [fedora-all]
1181946 – CVE-2015-0221 python-django: Django: denial of service attack against django.views.static.serve [fedora-all]
1179679 – CVE-2015-0221 Django: denial of service attack against django.views.static.serve
1179672 – CVE-2015-0219 Django: WSGI header spoofing via underscore/dash conflation
1179675 – CVE-2015-0220 Django: Mitigated possible XSS attack via user-supplied redirect URLs
1179685 – CVE-2015-0222 Django: database denial of service with ModelMultipleChoiceField
1181943 – CVE-2015-0220 python-django: Django: Mitigated possible XSS attack via user-supplied redirect URLs [fedora-all]
1181951 – CVE-2015-0222 python-django: Django: database denial of service with ModelMultipleChoiceField [fedora-all]<br
fix CVE-2015-0219 (rhbz#1181939)

Leave a Reply