Resource management error in Django - CVE-2014-0474
Published: April 23, 2014 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."
Affected software
Gentoo Linux
Fedora
py-django (Alpine package)
Django14
How to mitigate CVE-2014-0474
py-django (Alpine package) - update to 1.5.6-r0
Django14 - update to 1.4.11-1.el6
External References
- http://lists.opensuse.org/opensuse-updates/2014-09/msg00023.html
- http://rhn.redhat.com/errata/RHSA-2014-0456.html
- http://rhn.redhat.com/errata/RHSA-2014-0457.html
- http://secunia.com/advisories/61281
- http://www.debian.org/security/2014/dsa-2934
- http://www.ubuntu.com/usn/USN-2169-1
- https://www.djangoproject.com/weblog/2014/apr/21/security/