UbuntuUpdates.org

Package "python-django"

Name: python-django

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • High-level Python web development framework (documentation)
  • High-level Python web development framework

Latest version: 2:2.2.12-1ubuntu0.29
Release: focal (20.04)
Level: security
Repository: main

Links



Other versions of "python-django" in Focal

Repository Area Version
base main 2:2.2.12-1
updates main 2:2.2.12-1ubuntu0.29

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 2:2.2.12-1ubuntu0.29 2025-05-08 16:07:17 UTC

  python-django (2:2.2.12-1ubuntu0.29) focal-security; urgency=medium

  * SECURITY UPDATE: Denial of service in strip_tags()
    - debian/patches/CVE-2025-32873.patch: check tag depth in
      django/utils/html.py, tests/utils_tests/test_html.py.
    - CVE-2025-32873
  * Fix FTBFS due to failing test (LP: #2100643)
    - debian/patches/0012-FTBFS-skip-failing-ip-test-arg.patch: Remove ip
      bracket argument from test.

 -- Marc Deslauriers <email address hidden> Wed, 30 Apr 2025 10:35:25 -0400

Source diff to previous version
2100643 FTBFS on jammy due to python3.10 update
CVE-2025-32873 An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, ...

Version: 2:2.2.12-1ubuntu0.28 2025-03-06 23:07:08 UTC

  python-django (2:2.2.12-1ubuntu0.28) focal-security; urgency=medium

  * SECURITY UPDATE: Denial of service.
    - debian/patches/CVE-2025-26699.patch: Change wrap to use textwrap library
      in ./django/utils/text.py.
    - CVE-2025-26699

 -- Hlib Korzhynskyy <email address hidden> Fri, 28 Feb 2025 13:55:00 -0330

Source diff to previous version
CVE-2025-26699 An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, ...

Version: 2:2.2.12-1ubuntu0.27 2025-01-14 19:06:55 UTC

  python-django (2:2.2.12-1ubuntu0.27) focal-security; urgency=medium

  * SECURITY UPDATE: Denial of service
    - debian/patches/CVE-2024-56374.patch: mitigate potential
      DoS in IPv6 validation in django/db/models/fields/__init__.py.
      django/forms/fields.py, django/utils/ipv6.py,
      field_tests/test_genericipaddressfield.py,
      tests/utils_tests/test_ipv6.py.
    - CVE-2024-56374

 -- Leonidas Da Silva Barbosa <email address hidden> Thu, 09 Jan 2025 13:24:59 -0300

Source diff to previous version

Version: 2:2.2.12-1ubuntu0.26 2024-12-05 06:06:53 UTC

  python-django (2:2.2.12-1ubuntu0.26) focal-security; urgency=medium

  * SECURITY UPDATE: Potential denial-of-service in
    django.utils.html.strip_tags()
    - debian/patches/CVE-2024-53907.patch: mitigated potential DoS in
      strip_tags() in django/utils/html.py, tests/utils_tests/test_html.py.
    - CVE-2024-53907
  * Fix FTBFS caused by more restrictive mail parsing in python3.8 security
    update
    - fix_ftbfs_mail_test.patch: used email.headerregistry.parser for
      parsing emails in sanitize_address() in django/core/mail/message.py,
      tests/mail/tests.py.

 -- Marc Deslauriers <email address hidden> Wed, 27 Nov 2024 08:37:38 -0500

Source diff to previous version
CVE-2024-53907 Potential denial-of-service in django.utils.html.strip_tags()

Version: 2:2.2.12-1ubuntu0.25 2024-09-03 19:07:01 UTC

  python-django (2:2.2.12-1ubuntu0.25) focal-security; urgency=medium

  * SECURITY UPDATE: Denial of service
    - debian/patches/CVE-2024-45230.patch: mitigate
      potential DoS in urlize and urlizetrunc template filters
      in django/utils/html.py,
      tests/template_tests/filter_tests/test_urlize.py,
      tests/utils_tests/test_html.py.
    - CVE-2024-45230
  * SECURITY UPDATE: User email enumeration
    - debian/patches/CVE-2024-45231.patch: avoid
      server error on password reset when email sending fails
      in django/contrib/auth/forms.py,
      tests/auth_tests/test_forms.py,
      tests/mail/custombackend.py.
    - CVE-2024-45231

 -- Leonidas Da Silva Barbosa <email address hidden> Tue, 27 Aug 2024 14:05:52 -0300




About   -   Send Feedback to @ubuntu_updates