{
  "schema_version": "1.6.2",
  "id": "MGASA-2014-0196",
  "published": "2014-04-28T15:54:39Z",
  "modified": "2014-04-28T15:54:11Z",
  "summary": "Updated python-django packages fix multiple vulnerabilities",
  "details": "Updated python-django and python-dgango14 packages fix security vulnerabilities:\n\nBenjamin Bach discovered that Django incorrectly handled dotted Python\npaths when using the reverse() function. An attacker could use this issue\nto cause Django to import arbitrary modules from the Python path, resulting\nin possible code execution. (CVE-2014-0472)\n\nPaul McMillan discovered that Django incorrectly cached certain pages that\ncontained CSRF cookies. An attacker could possibly use this flaw to obtain\na valid cookie and perform attacks which bypass the CSRF restrictions.\n(CVE-2014-0473)\n\nMichael Koziarski discovered that Django did not always perform explicit\nconversion of certain fields when using a MySQL database. An attacker\ncould possibly use this issue to obtain unexpected results. (CVE-2014-0474)\n",
  "related": [
    "CVE-2014-0472",
    "CVE-2014-0473",
    "CVE-2014-0474"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2014-0196.html"
    },
    {
      "type": "REPORT",
      "url": "https://www.djangoproject.com/weblog/2014/apr/21/security/"
    },
    {
      "type": "REPORT",
      "url": "http://www.ubuntu.com/usn/usn-2169-1/"
    },
    {
      "type": "REPORT",
      "url": "http://www.ubuntu.com/usn/usn-2169-2/"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=13251"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:3",
        "name": "python-django",
        "purl": "pkg:rpm/mageia/python-django?arch=source&distro=mageia-3"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.4.11-1.1.mga3"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:4",
        "name": "python-django",
        "purl": "pkg:rpm/mageia/python-django?arch=source&distro=mageia-4"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.5.6-1.1.mga4"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:4",
        "name": "python-django14",
        "purl": "pkg:rpm/mageia/python-django14?arch=source&distro=mageia-4"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.4.11-1.1.mga4"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
