Branches for Raring

Name Status Last Modified Last Commit
lp:ubuntu/raring/python-django 2 Mature 2013-02-24 10:28:08 UTC
45. * New upstream maintenance release dr...

Author: Raphaël Hertzog
Revision Date: 2013-02-24 10:28:08 UTC

* New upstream maintenance release dropping some undesired .pyc files
  and fixing a documentation link.
* High urgency due to former security updates.

lp:ubuntu/raring-security/python-django bug 2 Mature 2013-10-30 02:07:21 UTC
46. * SECURITY UPDATE: denial of service ...

Author: Marc Deslauriers
Revision Date: 2013-09-20 08:48:09 UTC

* SECURITY UPDATE: denial of service via long passwords (LP: #1225784)
  - debian/patches/CVE-2013-1443.patch: enforce a maximum password length
    in django/contrib/auth/forms.py, django/contrib/auth/hashers.py,
    django/contrib/auth/tests/hashers.py.
  - CVE-2013-1443
* SECURITY UPDATE: directory traversal with ssi template tag
  - debian/patches/CVE-2013-4315.patch: properly check absolute path in
    django/template/defaulttags.py,
    tests/regressiontests/templates/tests.py.
  - CVE-2013-4315
* SECURITY UPDATE: possible XSS via is_safe_url
  - debian/patches/security-is_safe_url.patch: properly reject URLs which
    specify a scheme other then HTTP or HTTPS.
  - https://www.djangoproject.com/weblog/2013/aug/13/security-releases-issued/
  - No CVE number
* debian/patches/fix-validation-tests.patch: fix regression in tests
  since example.com is now available via https.

lp:ubuntu/raring-updates/python-django 2 Mature 2013-10-30 02:07:24 UTC
46. * SECURITY UPDATE: denial of service ...

Author: Marc Deslauriers
Revision Date: 2013-09-20 08:48:09 UTC

* SECURITY UPDATE: denial of service via long passwords (LP: #1225784)
  - debian/patches/CVE-2013-1443.patch: enforce a maximum password length
    in django/contrib/auth/forms.py, django/contrib/auth/hashers.py,
    django/contrib/auth/tests/hashers.py.
  - CVE-2013-1443
* SECURITY UPDATE: directory traversal with ssi template tag
  - debian/patches/CVE-2013-4315.patch: properly check absolute path in
    django/template/defaulttags.py,
    tests/regressiontests/templates/tests.py.
  - CVE-2013-4315
* SECURITY UPDATE: possible XSS via is_safe_url
  - debian/patches/security-is_safe_url.patch: properly reject URLs which
    specify a scheme other then HTTP or HTTPS.
  - https://www.djangoproject.com/weblog/2013/aug/13/security-releases-issued/
  - No CVE number
* debian/patches/fix-validation-tests.patch: fix regression in tests
  since example.com is now available via https.

lp:ubuntu/raring-proposed/python-django bug 1 Development 2013-02-24 10:28:08 UTC
45. * New upstream maintenance release dr...

Author: Raphaël Hertzog
Revision Date: 2013-02-24 10:28:08 UTC

* New upstream maintenance release dropping some undesired .pyc files
  and fixing a documentation link.
* High urgency due to former security updates.

14 of 4 results