CVE-2012-3443
Publication date 31 July 2012
Last updated 24 July 2024
Ubuntu priority
The django.forms.ImageField class in the form system in Django before 1.3.2 and 1.4.x before 1.4.1 completely decompresses image data during image validation, which allows remote attackers to cause a denial of service (memory consumption) by uploading an image file.
Status
Package | Ubuntu Release | Status |
---|---|---|
python-django | ||
Notes
Patch details
Package | Patch details |
---|---|
python-django |
|
References
Related Ubuntu Security Notices (USN)
- USN-1560-1
- Django vulnerabilities
- 10 September 2012