oss-sec mailing list archives

Re: CVE id request: django


From: Josh Bressers <bressers () redhat com>
Date: Mon, 12 Oct 2009 12:11:31 -0400 (EDT)

Please use CVE-2009-3610

Thanks.

----- "Raphael Geissert" <geissert () debian org> wrote:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi,

A vulnerability has been found in Django's forms library that can be
used to
perform DoS attacks via certain email addresses or URLs that make the
validation regular expressions consume CPU resources.

The vulnerability is said to be being exploited on live
installations.

References:
http://www.djangoproject.com/weblog/2009/oct/09/security/
http://groups.google.com/group/django-users/browse_thread/thread/15df9e45118dfc51/677e54bd6c6e283b
http://lists.debian.org/debian-security-announce/2009/msg00227.html

Please assign a CVE identifier.

Kind regards,
- -- 
Raphael Geissert - Debian Developer
www.debian.org - get.debian.net

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkrREJQACgkQYy49rUbZzlpwswCgjSOAiDSfYGYiE+ZjE9i6+Zmf
3MkAoJN9qvxGAzfzsgiFW8XAuP1wan81
=nsNz
-----END PGP SIGNATURE-----

-- 
    JB


Current thread: