Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2023-41164

Published: 4 September 2023

[Potential denial of service vulnerability in django.utils.encoding.uri_to_iri()]

Notes

AuthorNote
alexmurray
According to the upstream advisory affects versions 3.2.x,
4.1.x and 4.2.x with fixes in 3.2.21, 4.1.11 and 4.2.5 respectively

Priority

Medium

Status

Package Release Status
python-django
Launchpad, Ubuntu, Debian
trusty Needs triage

xenial Needed

bionic Needed

focal
Released (2:2.2.12-1ubuntu0.19)
jammy
Released (2:3.2.12-2ubuntu1.8)
lunar
Released (3:3.2.18-1ubuntu0.4)
upstream
Released (3.2.21,4.1.11,4.2.5)
Patches:
upstream: https://github.com/django/django/commit/3f41d6d62929dfe53eda8109b3b836f26645bdce (main)
upstream: https://github.com/django/django/commit/9c51b4dcfa0cefcb48231f4d71cafa80821f87b9 (4.2)
upstream: https://github.com/django/django/commit/ba00bc5ec6a7eff5e08be438f7b5b0e9574e8ff0 (4.1)
upstream: https://github.com/django/django/commit/6f030b1149bd8fa4ba90452e77cb3edc095ce54e (3.2)