The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
http://www.ubuntu.com/usn/USN-2169-1 | vendor advisory |
https://www.djangoproject.com/weblog/2014/apr/21/security/ | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2014-0457.html | vendor advisory |
http://secunia.com/advisories/61281 | third party advisory |
http://www.debian.org/security/2014/dsa-2934 | vendor advisory |
http://lists.opensuse.org/opensuse-updates/2014-09/msg00023.html | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2014-0456.html | vendor advisory |