Oct 2009 security update is not merged in 1.0.2-1ubuntu0.1

Bug #478328 reported by aberrant
264
This bug affects 1 person
Affects Status Importance Assigned to Milestone
python-django (Ubuntu)
Fix Released
Medium
Unassigned

Bug Description

Binary package hint: python-django

1.0.2-1ubuntu0.1 does not have the URLField / EmailField DoS vulnerability (http://www.djangoproject.com/weblog/2009/oct/09/security/) fixed. It appears to have been merged into 1.1.1-1 (karmic) but jaunty systems are still vulnerable as of 8 Nov 2009.

CVE References

Kees Cook (kees)
Changed in python-django (Ubuntu):
status: New → Confirmed
importance: Undecided → Medium
visibility: private → public
Revision history for this message
Krzysztof Klimonda (kklimonda) wrote :

I have a patch ready for 1.0.2 but I remember having problems with getting our 1.0.2 to pass regression tests.. I'll investigate it further today and see if maybe I can do something about it.

Changed in python-django (Ubuntu):
assignee: nobody → Krzysztof Klimonda (kklimonda)
status: Confirmed → In Progress
Revision history for this message
Krzysztof Klimonda (kklimonda) wrote :

Well, this patch won't really make things worse that they are for sure. There are no more regression tests failing than with 1.0.2-1ubuntu0.1 so it should be safe.

Changed in python-django (Ubuntu):
assignee: Krzysztof Klimonda (kklimonda) → nobody
status: In Progress → Confirmed
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

ACK on the debdiff. I'm uploading now. Packages should be released soon.

Changed in python-django (Ubuntu):
status: Confirmed → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package python-django - 1.0.2-1ubuntu0.2

---------------
python-django (1.0.2-1ubuntu0.2) jaunty-security; urgency=low

  * SECURITY UPDATE: Certain email addresses/URLs can trigger
    a catastrophic backtracking situation, causing 100% CPU
    and server overload. (LP: #447617, LP: #478328)
    http://www.djangoproject.com/weblog/2009/oct/09/security/
    - Applied upstream changeset 11605
    - CVE-2009-3695
 -- Krzysztof Klimonda <email address hidden> Tue, 13 Oct 2009 21:59:00 +0200

Changed in python-django (Ubuntu):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.