python-django: security bump to version 1.7.3
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Wed, 14 Jan 2015 18:21:44 +0000 (15:21 -0300)
committerThomas Petazzoni <thomas.petazzoni@free-electrons.com>
Wed, 14 Jan 2015 18:26:12 +0000 (19:26 +0100)
Fixes:

CVE-2015-0219 - incorrectly handled underscores in WSGI headers. A
remote attacker could possibly use this issue to spoof headers in
certain environments.

CVE-2015-0220 - incorrectly handled user-supplied redirect URLs. A
remote attacker could possibly use this issue to perform a cross-site
scripting attack.

CVE-2015-0221 - incorrectly handled reading files in
django.views.static.serve(). A remote attacker could possibly use this
issue to cause Django to consume resources, resulting in a denial of
service.

CVE-2015-0222 - incorrectly handled forms with ModelMultipleChoiceField.
A remote attacker could possibly use this issue to cause a large number
of SQL queries, resulting in a database denial of service.

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
package/python-django/python-django.hash
package/python-django/python-django.mk

index 0195a13b0550286e09b7d49ffc49efb9557078d2..f51c9b4741a6dcd26d9a5873479f4f632bd6a423 100644 (file)
@@ -1,2 +1,2 @@
-# sha256 from https://www.djangoproject.com/m/pgp/Django-1.7.2.checksum.txt
-sha256 31c6c3c229f8c04b3be87e6afc3492903b57ec8f1188a47b6ae160d90cf653c8 Django-1.7.2.tar.gz
+# sha256 from https://www.djangoproject.com/m/pgp/Django-1.7.3.checksum.txt
+sha256 f226fb8aa438456968d403f6739de1cf2dad128db86f66ee2b41dfebe3645c5b        Django-1.7.3.tar.gz
index fcfa406c7a0fe03c5e40b7bd9ff1d0ed2a37b796..28f25bd272dc196f93b5e0f693e62c97df4953ff 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-PYTHON_DJANGO_VERSION = 1.7.2
+PYTHON_DJANGO_VERSION = 1.7.3
 PYTHON_DJANGO_SOURCE = Django-$(PYTHON_DJANGO_VERSION).tar.gz
 # The official Django site has an unpractical URL
 PYTHON_DJANGO_SITE = https://pypi.python.org/packages/source/D/Django/