Gentoo Archives: gentoo-announce

From: Chris Reffett <creffett@g.o>
To: gentoo-announce@g.o
Subject: [gentoo-announce] [ GLSA 201406-26 ] Django: Multiple vulnerabilities
Date: Thu, 26 Jun 2014 22:56:25
Message-Id: 53ACA3EF.3050805@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201406-26
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Django: Multiple vulnerabilities
9 Date: June 26, 2014
10 Bugs: #508514, #510382
11 ID: 201406-26
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found Django, the worst of which may
19 allow a remote attacker to execute code.
20
21 Background
22 ==========
23
24 Django is a Python-based web framework.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 dev-python/django < 1.6.5 >= 1.6.5
33 *>= 1.5.8
34 *>= 1.4.13
35
36 Description
37 ===========
38
39 Multiple vulnerabilities have been discovered in Django. Please review
40 the CVE identifiers referenced below for details.
41
42 Impact
43 ======
44
45 A remote attacker could execute code with the privileges of the
46 process, modify SQL queries, or disclose sensitive information.
47
48 Workaround
49 ==========
50
51 There is no known workaround at this time.
52
53 Resolution
54 ==========
55
56 All Django 1.6 users should upgrade to the latest version:
57
58 # emerge --sync
59 # emerge --ask --oneshot --verbose ">=dev-python/django-1.6.5"
60
61 All Django 1.5 users should upgrade to the latest version:
62
63 # emerge --sync
64 # emerge --ask --oneshot --verbose ">=dev-python/django-1.5.8"
65
66 All Django 1.4 users should upgrade to the latest version:
67
68 # emerge --sync
69 # emerge --ask --oneshot --verbose ">=dev-python/django-1.4.13"
70
71 References
72 ==========
73
74 [ 1 ] CVE-2014-0472
75 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0472
76 [ 2 ] CVE-2014-0473
77 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0473
78 [ 3 ] CVE-2014-0474
79 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0474
80 [ 4 ] CVE-2014-1418
81 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1418
82
83 Availability
84 ============
85
86 This GLSA and any updates to it are available for viewing at
87 the Gentoo Security Website:
88
89 http://security.gentoo.org/glsa/glsa-201406-26.xml
90
91 Concerns?
92 =========
93
94 Security is a primary focus of Gentoo Linux and ensuring the
95 confidentiality and security of our users' machines is of utmost
96 importance to us. Any security concerns should be addressed to
97 security@g.o or alternatively, you may file a bug at
98 https://bugs.gentoo.org.
99
100 License
101 =======
102
103 Copyright 2014 Gentoo Foundation, Inc; referenced text
104 belongs to its owner(s).
105
106 The contents of this document are licensed under the
107 Creative Commons - Attribution / Share Alike license.
108
109 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature