47
|
|
|
Seth Arnold |
1.4.1-2ubuntu0.7 |
9 years ago
|
|
|
46
|
|
|
Marc Deslauriers |
1.4.1-2ubuntu0.6 |
9 years ago
|
|
|
45
|
|
* SECURITY UPDATE: unexpected code execution using reverse() (LP: #1309779) - debian/patches/CVE-2014-0472.patch: added filtering to django/core/urlresolvers.py, added tests to tests/regressiontests/urlpatterns_reverse/nonimported_module.py, tests/regressiontests/urlpatterns_reverse/tests.py, tests/regressiontests/urlpatterns_reverse/urls.py, tests/regressiontests/urlpatterns_reverse/views.py. - CVE-2014-0472 * SECURITY UPDATE: caching of anonymous pages could reveal CSRF token (LP: #1309782) - debian/patches/CVE-2014-0473.patch: don't cache responses with a cookie in django/middleware/cache.py, added tests to tests/regressiontests/cache/tests.py. - CVE-2014-0473 * SECURITY UPDATE: MySQL typecasting issue (LP: #1309784) - debian/patches/CVE-2014-0474.patch: convert arguments to correct type in django/db/models/fields/__init__.py, updated docs in docs/howto/custom-model-fields.txt, docs/ref/databases.txt, docs/ref/models/querysets.txt, docs/topics/db/sql.txt, added tests to tests/regressiontests/model_fields/tests.py. - CVE-2014-0474 * debian/patches/fix_test_ftbfs.patch: fix ftbfs with upstream commit.
|
Marc Deslauriers |
1.4.1-2ubuntu0.5 |
9 years ago
|
|
|
44
|
|
|
Marc Deslauriers |
1.4.1-2ubuntu0.4 |
10 years ago
|
|
|
43
|
|
* SECURITY UPDATE: host header poisoning (LP: #1089337) - debian/patches/fix_get_host.patch: tighten host header validation in django/http/__init__.py, add info to docs/topics/security.txt, add tests to tests/regressiontests/requests/tests.py. - https://www.djangoproject.com/weblog/2012/dec/10/security/ - No CVE number * SECURITY UPDATE: redirect poisoning (LP: #1089337) - debian/patches/fix_redirect_poisoning.patch: tighten validation in django/contrib/auth/views.py, django/contrib/comments/views/comments.py, django/contrib/comments/views/moderation.py, django/contrib/comments/views/utils.py, django/utils/http.py, django/views/i18n.py, add tests to tests/regressiontests/comment_tests/tests/comment_view_tests.py, tests/regressiontests/comment_tests/tests/moderation_view_tests.py, tests/regressiontests/views/tests/i18n.py. - https://www.djangoproject.com/weblog/2012/dec/10/security/ - No CVE number * SECURITY UPDATE: host header poisoning (LP: #1130445) - debian/patches/add_allowed_hosts.patch: add new ALLOWED_HOSTS setting to django/conf/global_settings.py, django/conf/project_template/project_name/settings.py, django/contrib/auth/tests/views.py, django/contrib/contenttypes/tests.py, django/contrib/sites/tests.py, django/http/__init__.py, django/test/utils.py, add docs to docs/ref/settings.txt, docs/topics/security.txt, add tests to tests/regressiontests/csrf_tests/tests.py, tests/regressiontests/requests/tests.py. - https://www.djangoproject.com/weblog/2013/feb/19/security/ - No CVE number * SECURITY UPDATE: XML attacks (LP: #1130445) - debian/patches/CVE-2013-166x.patch: forbid DTDs, entity expansion, and external entities/DTDs in django/core/serializers/xml_serializer.py, add tests to tests/regressiontests/serializers_regress/tests.py. - https://www.djangoproject.com/weblog/2013/feb/19/security/ - CVE-2013-1664 - CVE-2013-1665 * SECURITY UPDATE: Data leakage via admin history log (LP: #1130445) - debian/patches/CVE-2013-0305.patch: add permission checks to history view in django/contrib/admin/options.py, add tests to tests/regressiontests/admin_views/tests.py. - https://www.djangoproject.com/weblog/2013/feb/19/security/ - CVE-2013-0305 * SECURITY UPDATE: Formset denial-of-service (LP: #1130445) - debian/patches/CVE-2013-0306.patch: limit maximum number of forms in django/forms/formsets.py, add docs to docs/topics/forms/formsets.txt, docs/topics/forms/modelforms.txt, add tests to tests/regressiontests/forms/tests/formsets.py, tests/regressiontests/generic_inline_admin/tests.py. - https://www.djangoproject.com/weblog/2013/feb/19/security/ - CVE-2013-0306
|
Marc Deslauriers |
1.4.1-2ubuntu0.3 |
11 years ago
|
|
|
42
|
|
|
Jamie Strandboge |
1.4.1-2ubuntu0.2 |
11 years ago
|
|
|
41
|
|
|
Jamie Strandboge |
1.4.1-2ubuntu0.1 |
11 years ago
|
|
|
40
|
|
|
Raphaël Hertzog |
1.4.1-2 |
11 years ago
|
|
|
39
|
|
|
Raphaël Hertzog |
1.4.1-1 |
11 years ago
|
|
|
38
|
|
|
Raphaël Hertzog |
1.4-1 |
12 years ago
|
|
|
37
|
|
|
Dave Walker (Daviey) |
1.3.1-4ubuntu1 |
12 years ago
|
|
|
36
|
|
|
Barry Warsaw |
1.3.1-1ubuntu1 |
12 years ago
|
|
|
35
|
|
|
Raphaël Hertzog |
1.3.1-1 |
12 years ago
|
|
|
34
|
|
|
Barry Warsaw |
1.3-2ubuntu1 |
12 years ago
|
|
|
33
|
|
|
Piotr Ożarowski |
1.3-2 |
12 years ago
|
|
|
32
|
|
|
Jamie Strandboge |
1.2.5-1ubuntu1 |
13 years ago
|
|
|
31
|
|
|
Jamie Strandboge |
1.2.3-1ubuntu0.2.11.04.1 |
13 years ago
|
|
|
30
|
|
|
Jamie Strandboge |
1.2.3-1ubuntu0.1 |
13 years ago
|
|
|
29
|
|
|
Chris Lamb |
1.2.1-1 |
13 years ago
|
|
|
28
|
|
|
Chris Lamb |
1.2-1 |
13 years ago
|
|
|