5

CVE-2015-0221

Exploit

The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.

Data is provided by the National Vulnerability Database (NVD)
DjangoprojectDjango Version <= 1.4.17
DjangoprojectDjango Version1.6
DjangoprojectDjango Version1.6.1
DjangoprojectDjango Version1.6.2
DjangoprojectDjango Version1.6.3
DjangoprojectDjango Version1.6.4
DjangoprojectDjango Version1.6.5
DjangoprojectDjango Version1.6.6
DjangoprojectDjango Version1.6.7
DjangoprojectDjango Version1.6.8
DjangoprojectDjango Version1.6.9
DjangoprojectDjango Version1.7
DjangoprojectDjango Version1.7.1
DjangoprojectDjango Version1.7.2
CanonicalUbuntu Linux Version10.04 Editionlts
CanonicalUbuntu Linux Version12.04 Editionlts
CanonicalUbuntu Linux Version14.04 SwEditionlts
CanonicalUbuntu Linux Version14.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 11.72% 0.935
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P