5
CVSSv2

CVE-2015-2316

Published: 25/03/2015 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The utils.html.strip_tags function in Django 1.6.x prior to 1.6.11, 1.7.x prior to 1.7.7, and 1.8.x prior to 1.8c1, when using certain versions of Python, allows remote malicious users to cause a denial of service (infinite loop) by increasing the length of the input string.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle solaris 11.2

djangoproject django 1.6.10

djangoproject django 1.6.2

djangoproject django 1.6.1

djangoproject django 1.7

djangoproject django 1.7.3

djangoproject django 1.7.4

djangoproject django 1.6.4

djangoproject django 1.6.3

djangoproject django 1.6

djangoproject django 1.7.1

djangoproject django 1.7.2

djangoproject django 1.6.7

djangoproject django 1.6.6

djangoproject django 1.6.5

djangoproject django 1.6.9

djangoproject django 1.6.8

djangoproject django 1.7.5

djangoproject django 1.7.6

djangoproject django 1.8.0

canonical ubuntu linux 10.04

canonical ubuntu linux 12.04

opensuse opensuse 13.2

canonical ubuntu linux 14.10

fedoraproject fedora 22

canonical ubuntu linux 14.04

Vendor Advisories

Several security issues were fixed in Django ...
Debian Bug report logs - #780874 python-django: CVE-2015-2316: Denial-of-service possibility with strip_tags() Package: src:python-django; Maintainer for src:python-django is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 20 Ma ...
Debian Bug report logs - #780873 python-django: CVE-2015-2317 Mitigated possible XSS attack via user-supplied redirect URLs Package: src:python-django; Maintainer for src:python-django is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Dat ...
The utilshtmlstrip_tags function in Django 16x before 1611, 17x before 177, and 18x before 18c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string ...