CVE-2015-5964
Published: 18 August 2015
The (1) contrib.sessions.backends.base.SessionBase.flush and (2) cache_db.SessionStore.flush functions in Django 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions create empty sessions in certain circumstances, which allows remote attackers to cause a denial of service (session store consumption) via unspecified vectors.
Priority
Status
Package | Release | Status |
---|---|---|
python-django Launchpad, Ubuntu, Debian |
precise |
Released
(1.3.1-4ubuntu1.18)
|
trusty |
Released
(1.6.1-2ubuntu0.10)
|
|
upstream |
Released
(1.4.22,1.7.10,1.8.4)
|
|
vivid |
Released
(1.7.6-1ubuntu2.2)
|