python-django 1.1.1-1ubuntu1.2 source package in Ubuntu

Changelog

python-django (1.1.1-1ubuntu1.2) karmic-security; urgency=low

  * SECURITY UPDATE: flaw in CSRF handling (LP: #719031)
    - debian/patches/24_CVE-2011-0696.diff: apply full CSRF validation to all
      requests, regardless of apparent AJAX origin. This is technically
      backwards-incompatible, but the security risks have been judged to
      outweigh the compatibility concerns in this case. See the Django project
      notes for more information:
      http://www.djangoproject.com/weblog/2011/feb/08/security/
    - CVE-2011-0696
  * SECURITY UPDATE: potential XSS in file field rendering
    - debian/patches/25_CVE-2011-0697.diff: properly escape URL in
      django/contrib/admin/widgets.py
    - CVE-2011-0697
 -- Jamie Strandboge <email address hidden>   Tue, 15 Feb 2011 17:18:54 -0600

Upload details

Uploaded by:
Jamie Strandboge
Uploaded to:
Karmic
Original maintainer:
Ubuntu Developers
Architectures:
all
Section:
python
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Karmic: [FULLYBUILT] i386

Downloads

File Size SHA-256 Checksum
python-django_1.1.1.orig.tar.gz 5.4 MiB d65b18319496fc4923b37fdb736e5ba1a90a3a18e2d7eaac7f3ad30738d1f6e4
python-django_1.1.1-1ubuntu1.2.diff.gz 22.6 KiB 3f571d203c827937fac53dbd3c3394fc8674218071ca9810f5c27c17e63718e1
python-django_1.1.1-1ubuntu1.2.dsc 2.2 KiB 3eac717503981b4dc9f5def5271a20d3bb3b5474ddc7610d9a9f86a408d17e9e

View changes file

Binary packages built by this source

python-django: No summary available for python-django in ubuntu karmic.

No description available for python-django in ubuntu karmic.

python-django-doc: No summary available for python-django-doc in ubuntu karmic.

No description available for python-django-doc in ubuntu karmic.