CVE Vulnerabilities

CVE-2013-0306

Published: May 02, 2013 | Modified: May 15, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu

The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_num parameter.

Affected Software

Name Vendor Start Version End Version
Django Djangoproject 1.3 1.3
Django Djangoproject 1.3 1.3
Django Djangoproject 1.3 1.3
Django Djangoproject 1.3.1 1.3.1
Django Djangoproject 1.3.2 1.3.2
Django Djangoproject 1.3.3 1.3.3
OpenStack Folsom for RHEL 6 RedHat Django14-0:1.4.4-1.el6ost *
Python-django Ubuntu hardy *
Python-django Ubuntu lucid *
Python-django Ubuntu oneiric *
Python-django Ubuntu precise *
Python-django Ubuntu quantal *
Python-django Ubuntu upstream *

References