CVE-2010-4535
Publication date 22 December 2010
Last updated 24 July 2024
Ubuntu priority
The password reset functionality in django.contrib.auth in Django before 1.1.3, 1.2.x before 1.2.4, and 1.3.x before 1.3 beta 1 does not validate the length of a string representing a base36 timestamp, which allows remote attackers to cause a denial of service (resource consumption) via a URL that specifies a large base36 integer.
Status
Package | Ubuntu Release | Status |
---|---|---|
python-django | ||
Patch details
Package | Patch details |
---|---|
python-django |
References
Related Ubuntu Security Notices (USN)
- USN-1040-1
- Django vulnerabilities
- 7 January 2011