FreeBSD : django -- denial-of-service attack (87917d6f-ba76-11de-bac2-001a4d563a0f)

medium Nessus Plugin ID 42170

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

Django project reports :

Django's forms library includes field types which perform regular-expression-based validation of email addresses and URLs.
Certain addresses/URLs could trigger a pathological performance case in these regular expression, resulting in the server process/thread becoming unresponsive, and consuming excessive CPU over an extended period of time. If deliberately triggered, this could result in an effectively denial-of-service attack.

Solution

Update the affected packages.

See Also

https://www.djangoproject.com/weblog/2009/oct/09/security/

http://www.nessus.org/u?e3344ff1

Plugin Details

Severity: Medium

ID: 42170

File Name: freebsd_pkg_87917d6fba7611debac2001a4d563a0f.nasl

Version: 1.11

Type: local

Published: 10/19/2009

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:py23-django, p-cpe:/a:freebsd:freebsd:py23-django-devel, p-cpe:/a:freebsd:freebsd:py24-django, p-cpe:/a:freebsd:freebsd:py24-django-devel, p-cpe:/a:freebsd:freebsd:py25-django, p-cpe:/a:freebsd:freebsd:py25-django-devel, p-cpe:/a:freebsd:freebsd:py26-django, p-cpe:/a:freebsd:freebsd:py26-django-devel, p-cpe:/a:freebsd:freebsd:py30-django, p-cpe:/a:freebsd:freebsd:py30-django-devel, p-cpe:/a:freebsd:freebsd:py31-django, p-cpe:/a:freebsd:freebsd:py31-django-devel, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 10/16/2009

Vulnerability Publication Date: 10/9/2009

Reference Information

CVE: CVE-2009-3695