openSUSE Security Update : python-django (openSUSE-SU-2013:1203-1)

medium Nessus Plugin ID 75089

Synopsis

The remote openSUSE host is missing a security update.

Description

python-django was updated to 1.4.5 to fix various security issues and bugs.

Update to 1.4.5 :

- Security release.

- Fix bnc#807175 / bnc#787521 / CVE-2012-4520 / CVE-2013-0305 / CVE-2013-0306 and CVE-2013-1665.

- Update to 1.4.3 :

- Security release :

- Host header poisoning

- Redirect poisoning

- Please check release notes for details:
https://www.djangoproject.com/weblog/2012/dec/10/securit y

- Add a symlink from /usr/bin/django-admin.py to /usr/bin/django-admin

- Update to 1.4.2 :

- Security release :

- Host header poisoning

- Please check release notes for details:
https://www.djangoproject.com/weblog/2012/oct/17/securit y

- Update to 1.4.1 :

- Security release :

- Cross-site scripting in authentication views

- Denial-of-service in image validation

- Denial-of-service via get_image_dimensions()

- Please check release notes for details:
https://www.djangoproject.com/weblog/2012/jul/30/securit y-releases-issued

- Add patch to support CSRF_COOKIE_HTTPONLY config

Solution

Update the affected python-django package.

See Also

https://bugzilla.novell.com/show_bug.cgi?id=787521

https://bugzilla.novell.com/show_bug.cgi?id=807175

https://lists.opensuse.org/opensuse-updates/2013-07/msg00058.html

https://www.djangoproject.com/weblog/2012/dec/10/security/

http://www.nessus.org/u?85c9c56c

https://www.djangoproject.com/weblog/2012/oct/17/security/

Plugin Details

Severity: Medium

ID: 75089

File Name: openSUSE-2013-589.nasl

Version: 1.7

Type: local

Agent: unix

Published: 6/13/2014

Updated: 1/19/2021

Supported Sensors: Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.7

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 4.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:python-django, cpe:/o:novell:opensuse:12.2, cpe:/o:novell:opensuse:12.3

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 7/9/2013

Reference Information

CVE: CVE-2012-4520, CVE-2013-0305, CVE-2013-0306, CVE-2013-1665