Daniel Chatfield discovered that python-django, a high-level Python web development framework, incorrectly handled user-supplied redirect URLs. A remote attacker could use this flaw to perform a cross-site scripting attack. For the stable distribution (wheezy), this problem has been fixed in version 1.4.5-1+deb7u11. For the unstable distribution (sid), this problem has been fixed in version 1.7.7-1. We recommend that you upgrade your python-django packages.
Daniel Chatfield discovered that python-django, a high-level Python web development framework, incorrectly handled user-supplied redirect URLs. A remote attacker could use this flaw to perform a cross-site scripting attack.
For the stable distribution (wheezy), this problem has been fixed in version 1.4.5-1+deb7u11.
For the unstable distribution (sid), this problem has been fixed in version 1.7.7-1.
We recommend that you upgrade your python-django packages.