2.6

CVE-2007-5712

The internationalization (i18n) framework in Django 0.91, 0.95, 0.95.1, and 0.96, and as used in other products such as PyLucid, when the USE_I18N option and the i18n component are enabled, allows remote attackers to cause a denial of service (memory consumption) via many HTTP requests with large Accept-Language headers.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Django ProjectDjango Version0.91
Django ProjectDjango Version0.95
Django ProjectDjango Version0.95.1
Django ProjectDjango Version0.96
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.8% 0.756
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/27435
Patch
Vendor Advisory
http://secunia.com/advisories/27597
Vendor Advisory
http://secunia.com/advisories/31961
Vendor Advisory
http://sourceforge.net/forum/forum.php?forum_id=749199
http://www.debian.org/security/2008/dsa-1640
Patch
http://www.djangoproject.com/weblog/2007/oct/26/security-fix
Patch
http://www.securityfocus.com/bid/26227
http://www.vupen.com/english/advisories/2007/3660
Vendor Advisory
http://www.vupen.com/english/advisories/2007/3661
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/38143
https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00243.html
https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00257.html