DSA-3204-1 python-django -- security update

Related Vulnerabilities: CVE-2015-2317  

Daniel Chatfield discovered that python-django, a high-level Python web development framework, incorrectly handled user-supplied redirect URLs. A remote attacker could use this flaw to perform a cross-site scripting attack. For the stable distribution (wheezy), this problem has been fixed in version 1.4.5-1+deb7u11. For the unstable distribution (sid), this problem has been fixed in version 1.7.7-1. We recommend that you upgrade your python-django packages.

Debian Security Advisory

DSA-3204-1 python-django -- security update

Date Reported:
24 Mar 2015
Affected Packages:
python-django
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 780873.
In Mitre's CVE dictionary: CVE-2015-2317.
More information:

Daniel Chatfield discovered that python-django, a high-level Python web development framework, incorrectly handled user-supplied redirect URLs. A remote attacker could use this flaw to perform a cross-site scripting attack.

For the stable distribution (wheezy), this problem has been fixed in version 1.4.5-1+deb7u11.

For the unstable distribution (sid), this problem has been fixed in version 1.7.7-1.

We recommend that you upgrade your python-django packages.