CVE Vulnerabilities

CVE-2015-0221

Published: Jan 16, 2015 | Modified: Dec 22, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.

Affected Software

Name Vendor Start Version End Version
Django Djangoproject * 1.4.17 (including)
Django Djangoproject 1.6 (including) 1.6 (including)
Django Djangoproject 1.6.1 (including) 1.6.1 (including)
Django Djangoproject 1.6.2 (including) 1.6.2 (including)
Django Djangoproject 1.6.3 (including) 1.6.3 (including)
Django Djangoproject 1.6.4 (including) 1.6.4 (including)
Django Djangoproject 1.6.5 (including) 1.6.5 (including)
Django Djangoproject 1.6.6 (including) 1.6.6 (including)
Django Djangoproject 1.6.7 (including) 1.6.7 (including)
Django Djangoproject 1.6.8 (including) 1.6.8 (including)
Django Djangoproject 1.6.9 (including) 1.6.9 (including)
Django Djangoproject 1.7 (including) 1.7 (including)
Django Djangoproject 1.7.1 (including) 1.7.1 (including)
Django Djangoproject 1.7.2 (including) 1.7.2 (including)
Python-django Ubuntu devel *
Python-django Ubuntu lucid *
Python-django Ubuntu precise *
Python-django Ubuntu trusty *
Python-django Ubuntu upstream *
Python-django Ubuntu utopic *

References