Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2015-2317

Published: 19 March 2015

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

Priority

Medium

Status

Package Release Status
python-django
Launchpad, Ubuntu, Debian
lucid
Released (1.1.1-2ubuntu1.17)
precise
Released (1.3.1-4ubuntu1.16)
trusty
Released (1.6.1-2ubuntu0.8)
upstream
Released (1.4.20,1.6.11,1.7.7,1.8c1)
utopic
Released (1.6.6-1ubuntu2.2)
Patches:
upstream: https://github.com/django/django/commit/2a4113dbd532ce952308992633d802dc169a75f1
upstream: https://github.com/django/django/commit/5510f070711540aaa8d3707776cd77494e688ef9
upstream: https://github.com/django/django/commit/2342693b31f740a422abf7267c53b4e7bc487c1b