CVE Vulnerabilities

CVE-2009-3695

Published: Oct 13, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Algorithmic complexity vulnerability in the forms library in Django 1.0 before 1.0.4 and 1.1 before 1.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a crafted (1) EmailField (email address) or (2) URLField (URL) that triggers a large amount of backtracking in a regular expression.

Affected Software

NameVendorStart VersionEnd Version
DjangoDjangoproject1.0 (including)1.0 (including)
DjangoDjangoproject1.1 (including)1.1 (including)
Python-djangoUbuntuhardy*
Python-djangoUbuntuintrepid*
Python-djangoUbuntujaunty*

References