CVE Vulnerabilities

CVE-2015-0221

Published: Jan 16, 2015 | Modified: Dec 22, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.

Affected Software

Name Vendor Start Version End Version
Django Djangoproject * 1.4.17
Django Djangoproject 1.6.7 1.6.7
Django Djangoproject 1.6.5 1.6.5
Django Djangoproject 1.6.8 1.6.8
Django Djangoproject 1.6.6 1.6.6
Django Djangoproject 1.7.2 1.7.2
Django Djangoproject 1.6.3 1.6.3
Django Djangoproject 1.6 1.6
Django Djangoproject 1.6.4 1.6.4
Django Djangoproject 1.6.1 1.6.1
Django Djangoproject 1.6.2 1.6.2
Django Djangoproject 1.7 1.7
Django Djangoproject 1.6.9 1.6.9
Django Djangoproject 1.7.1 1.7.1

References