SB2012101802 - Fedora EPEL 6 update for Django, Django14 



SB2012101802 - Fedora EPEL 6 update for Django, Django14

Published: October 18, 2012 Updated: April 24, 2025

Security Bulletin ID SB2012101802
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Input validation error (CVE-ID: CVE-2012-4520)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.


Remediation

Install update from vendor's website.