MDVSA-2011:031
- Package name
- python-django
- Date
- 2011-02-18
- Advisory ID
- MDVSA-2011:031
- Affected versions
- 2010.1 x86_64 , 2010.1 i586 , 2010.0 x86_64 , 2010.0 i586
Problem description
Multiple vulnerabilities has been found and corrected in python-django:
Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 does not properly
validate HTTP requests that contain an X-Requested-With header,
which makes it easier for remote attackers to conduct cross-site
request forgery (CSRF) attacks via forged AJAX requests that leverage
a combination of browser plugins and redirects, a related issue to
CVE-2011-0447 (CVE-2011-0696).
Cross-site scripting (XSS) vulnerability in Django 1.1.x before
1.1.4 and 1.2.x before 1.2.5 might allow remote attackers to inject
arbitrary web script or HTML via a filename associated with a file
upload (CVE-2011-0697).
Directory traversal vulnerability in Django 1.1.x before 1.1.4 and
1.2.x before 1.2.5 on Windows might allow remote attackers to read or
execute files via a / (slash) character in a key in a session cookie,
related to session replays (CVE-2011-0698).
The updated packages have been upgraded to the 1.1.4 version which
is not vulnerable to these issues.
Updated packages
2010.1 x86_64
50a8a8aad7dd3001bee2560f8df1b156 2010.1/x86_64/python-django-1.1.4-0.1mdv2010.2.noarch.rpm 4f628f112373a36feebb403daec0e646 2010.1/SRPMS/python-django-1.1.4-0.1mdv2010.2.src.rpm
2010.1 i586
3cfc441c4f75142c19416c6f6d22eb2d 2010.1/i586/python-django-1.1.4-0.1mdv2010.2.noarch.rpm 4f628f112373a36feebb403daec0e646 2010.1/SRPMS/python-django-1.1.4-0.1mdv2010.2.src.rpm
2010.0 x86_64
33eb96488eced9ae1d573bb6f2706058 2010.0/x86_64/python-django-1.1.4-0.1mdv2010.0.noarch.rpm ba04206d09a47c76d3e5b0e60dbad79f 2010.0/SRPMS/python-django-1.1.4-0.1mdv2010.0.src.rpm
2010.0 i586
202f769807a186f2d9197c9eda30faa6 2010.0/i586/python-django-1.1.4-0.1mdv2010.0.noarch.rpm ba04206d09a47c76d3e5b0e60dbad79f 2010.0/SRPMS/python-django-1.1.4-0.1mdv2010.0.src.rpm
