Wind River Support Network

HomeDefectsLIN9-10031
Fixed

LIN9-10031 : Security Advisory - python3-django - CVE-2018-7536

Created: Jun 8, 2020    Updated: Aug 20, 2020
Resolved Date: Jul 30, 2020
Previous ID: LIN10-7432
Found In Version: 9.0.0.24
Fix Version: 9.0.0.26
Severity: Standard
Applicable for: Wind River Linux 9
Component/s: Userspace

Description

An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. The django.utils.html.urlize() function was extremely slow to evaluate certain inputs due to catastrophic backtracking vulnerabilities in two regular expressions (only one regular expression for Django 1.8.x). The urlize() function is used to implement the urlize and urlizetrunc template filters, which were thus vulnerable.

CREATE(Triage):(User=admin) [CVE-2018-7536|https://nvd.nist.gov/vuln/detail/CVE-2018-7536]

CVEs


Live chat
Online