[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

[3.8] py-django: memory exhaustion in django.utils.numberformat.format() (CVE-2019-6975)

ID: oval:org.secpod.oval:def:1801335Date: (C)2019-06-06   (M)2023-11-10
Class: PATCHFamily: unix




A vulnerability was found in Django before versions 2.2b1, 2.1.6, 2.0.11, 1.11.19. If django.utils.numberformat.format, used by contrib.admin as well as the the floatformat, filesizeformat, and intcomma templates filters, received a Decimal with a large number of digits or a large exponent, it could lead to significant memory usage due to a call to "{:f}".format. To avoid this, decimals with more than 200 digits are now formatted using scientific notation.

Platform:
Alpine Linux 3.8
Product:
py-django
Reference:
10005
CVE-2019-6975
CVE    1
CVE-2019-6975
CPE    2
cpe:/o:alpinelinux:alpine_linux:3.8
cpe:/a:djangoproject:py-django

© SecPod Technologies