CVE Vulnerabilities

CVE-2014-0474

Published: Apr 23, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to MySQL typecasting.

Affected Software

NameVendorStart VersionEnd Version
Ubuntu_linuxCanonical10.04 (including)10.04 (including)
Ubuntu_linuxCanonical12.04 (including)12.04 (including)
Ubuntu_linuxCanonical12.10 (including)12.10 (including)
Ubuntu_linuxCanonical13.10 (including)13.10 (including)
Ubuntu_linuxCanonical14.04 (including)14.04 (including)
OpenStack 3 for RHEL 6RedHatDjango14-0:1.4.11-1.el6ost*
OpenStack 4 for RHEL 6RedHatDjango14-0:1.4.11-1.el6ost*
Python-djangoUbuntuesm-infra-legacy/trusty*
Python-djangoUbuntulucid*
Python-djangoUbuntuprecise*
Python-djangoUbuntuquantal*
Python-djangoUbuntusaucy*
Python-djangoUbuntutrusty*
Python-djangoUbuntutrusty/esm*
Python-djangoUbuntuupstream*

References