DSA-2529-1 python-django -- severalID: oval:org.secpod.oval:def:600867 | Date: (C)2012-08-24 (M)2022-10-10 |
Class: PATCH | Family: unix |
Jeroen Dekkers and others reported several vulnerabilities in Django, a Python Web framework. The Common Vulnerabilities and Exposures project defines the following issues: CVE-2012-3442 Two functions do not validate the scheme of a redirect target, which might allow remote attackers to conduct cross-site scripting attacks via a data: URL. CVE-2012-3443 The ImageField class completely decompresses image data during image validation, which allows remote attackers to cause a denial of service by uploading an image file. CVE-2012-3444 The get_image_dimensions function in the image-handling functionality uses a constant chunk size in all attempts to determine dimensions, which allows remote attackers to cause a denial of service via a large TIFF image.