5

CVE-2015-2316

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.

Data is provided by the National Vulnerability Database (NVD)
OracleSolaris Version11.2
DjangoprojectDjango Version1.6 Update-
DjangoprojectDjango Version1.6 Updatebeta1
DjangoprojectDjango Version1.6 Updatebeta2
DjangoprojectDjango Version1.6 Updatebeta3
DjangoprojectDjango Version1.6 Updatebeta4
DjangoprojectDjango Version1.6.1
DjangoprojectDjango Version1.6.2
DjangoprojectDjango Version1.6.3
DjangoprojectDjango Version1.6.4
DjangoprojectDjango Version1.6.5
DjangoprojectDjango Version1.6.6
DjangoprojectDjango Version1.6.7
DjangoprojectDjango Version1.6.8
DjangoprojectDjango Version1.6.9
DjangoprojectDjango Version1.6.10
DjangoprojectDjango Version1.7 Updatebeta1
DjangoprojectDjango Version1.7 Updatebeta2
DjangoprojectDjango Version1.7 Updatebeta3
DjangoprojectDjango Version1.7 Updatebeta4
DjangoprojectDjango Version1.7 Updaterc1
DjangoprojectDjango Version1.7 Updaterc2
DjangoprojectDjango Version1.7 Updaterc3
DjangoprojectDjango Version1.7.1
DjangoprojectDjango Version1.7.2
DjangoprojectDjango Version1.7.3
DjangoprojectDjango Version1.7.4
DjangoprojectDjango Version1.7.5
DjangoprojectDjango Version1.7.6
DjangoprojectDjango Version1.8.0
CanonicalUbuntu Linux Version10.04 SwEditionlts
CanonicalUbuntu Linux Version12.04 SwEditionlts
CanonicalUbuntu Linux Version14.04 SwEditionlts
CanonicalUbuntu Linux Version14.10
FedoraprojectFedora Version22
OpensuseOpensuse Version13.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2% 0.83
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P