=========================================================================Ubuntu Security Notice USN-5837-2
February 01, 2023

python-django vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM

Summary:

Django could be made to consume memory if it received specially crafted
network traffic.

Software Description:
- python-django: High-level Python web development framework

Details:

USN-5837-1 fixed a vulnerability in Django. This update provides
the corresponding update for Ubuntu 16.04 ESM.

Original advisory details:

 Nick Pope discovered that Django incorrectly handled certain
 Accept-Language headers. A remote attacker could possibly use this issue to
 cause Django to consume memory, leading to a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
  python-django                   1.8.7-1ubuntu5.15+esm6
  python3-django                  1.8.7-1ubuntu5.15+esm6

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-5837-2
  https://ubuntu.com/security/notices/USN-5837-1
  CVE-2023-23969

Ubuntu 5837-2: Django vulnerability

February 1, 2023
Django could be made to consume memory if it received specially crafted network traffic.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: python-django 1.8.7-1ubuntu5.15+esm6 python3-django 1.8.7-1ubuntu5.15+esm6 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5837-2

https://ubuntu.com/security/notices/USN-5837-1

CVE-2023-23969

Severity
February 01, 2023

Package Information

Related News