Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.68996
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-2163-1)
Summary:The remote host is missing an update for the Debian 'python-django' package(s) announced via the DSA-2163-1 advisory.;; This VT has been deprecated and merged into the VT 'deb_2163.nasl' (OID: 1.3.6.1.4.1.25623.1.0.68996).
Description:Summary:
The remote host is missing an update for the Debian 'python-django' package(s) announced via the DSA-2163-1 advisory.

This VT has been deprecated and merged into the VT 'deb_2163.nasl' (OID: 1.3.6.1.4.1.25623.1.0.68996).

Vulnerability Insight:
Several vulnerabilities were discovered in the Django web development framework:

CVE-2011-0696

For several reasons the internal CSRF protection was not used to validate AJAX requests in the past. However, it was discovered that this exception can be exploited with a combination of browser plugins and redirects and thus is not sufficient.

CVE-2011-0697

It was discovered that the file upload form is prone to cross-site scripting attacks via the file name.

It is important to note that this update introduces minor backward incompatibilities due to the fixes for the above issues. For the exact details, please see: [link moved to references] and in particular the Backwards incompatible changes section.

Packages in the oldstable distribution (lenny) are not affected by these problems.

For the stable distribution (squeeze), this problem has been fixed in version 1.2.3-3+squeeze1.

For the testing distribution (wheezy), this problem will be fixed soon.

For the unstable distribution (sid), this problem has been fixed in version 1.2.5-1.

We recommend that you upgrade your python-django packages.

Affected Software/OS:
'python-django' package(s) on Debian 6.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-0696
43230
http://secunia.com/advisories/43230
43297
http://secunia.com/advisories/43297
43382
http://secunia.com/advisories/43382
43426
http://secunia.com/advisories/43426
46296
http://www.securityfocus.com/bid/46296
ADV-2011-0372
http://www.vupen.com/english/advisories/2011/0372
ADV-2011-0388
http://www.vupen.com/english/advisories/2011/0388
ADV-2011-0429
http://www.vupen.com/english/advisories/2011/0429
ADV-2011-0439
http://www.vupen.com/english/advisories/2011/0439
ADV-2011-0441
http://www.vupen.com/english/advisories/2011/0441
DSA-2163
http://www.debian.org/security/2011/dsa-2163
FEDORA-2011-1235
http://lists.fedoraproject.org/pipermail/package-announce/2011-February/054208.html
FEDORA-2011-1261
http://lists.fedoraproject.org/pipermail/package-announce/2011-February/054207.html
MDVSA-2011:031
http://www.mandriva.com/security/advisories?name=MDVSA-2011:031
USN-1066-1
http://www.ubuntu.com/usn/USN-1066-1
[oss-security] 20110209 Django multiple flaws (CVEs inside)
http://openwall.com/lists/oss-security/2011/02/09/6
http://www.djangoproject.com/weblog/2011/feb/08/security/
https://bugzilla.redhat.com/show_bug.cgi?id=676357
Common Vulnerability Exposure (CVE) ID: CVE-2011-0697
https://bugzilla.redhat.com/show_bug.cgi?id=676359
CopyrightCopyright (C) 2011 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.