CVE-2010-4535
Publication date 22 December 2010
Last updated 24 July 2024
Ubuntu priority
Description
The password reset functionality in django.contrib.auth in Django before 1.1.3, 1.2.x before 1.2.4, and 1.3.x before 1.3 beta 1 does not validate the length of a string representing a base36 timestamp, which allows remote attackers to cause a denial of service (resource consumption) via a URL that specifies a large base36 integer.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| python-django | ||
Patch details
| Package | Patch details |
|---|---|
| python-django |
References
Related Ubuntu Security Notices (USN)
- USN-1040-1
- Django vulnerabilities
- 7 January 2011