[<prev] [next>] [<thread-prev] [thread-next>] [month] [year] [list]
Date: Mon, 12 Oct 2009 12:11:31 -0400 (EDT)
From: Josh Bressers <bressers@...hat.com>
To: oss-security@...ts.openwall.com
Cc: coley@...re.org
Subject: Re: CVE id request: django
Please use CVE-2009-3610
Thanks.
----- "Raphael Geissert" <geissert@...ian.org> wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> Hi,
>
> A vulnerability has been found in Django's forms library that can be
> used to
> perform DoS attacks via certain email addresses or URLs that make the
> validation regular expressions consume CPU resources.
>
> The vulnerability is said to be being exploited on live
> installations.
>
> References:
> http://www.djangoproject.com/weblog/2009/oct/09/security/
> http://groups.google.com/group/django-users/browse_thread/thread/15df9e45118dfc51/677e54bd6c6e283b
> http://lists.debian.org/debian-security-announce/2009/msg00227.html
>
> Please assign a CVE identifier.
>
> Kind regards,
> - --
> Raphael Geissert - Debian Developer
> www.debian.org - get.debian.net
>
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.10 (GNU/Linux)
>
> iEYEARECAAYFAkrREJQACgkQYy49rUbZzlpwswCgjSOAiDSfYGYiE+ZjE9i6+Zmf
> 3MkAoJN9qvxGAzfzsgiFW8XAuP1wan81
> =nsNz
> -----END PGP SIGNATURE-----
--
JB
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Powered by Openwall GNU/*/Linux -
Powered by OpenVZ