USN-6414-2: Django vulnerabilities
USN-6414-1 and USN-6378-1 fixed CVE-2023-43665 and CVE-2023-41164 in Django, respectively. This update provides the corresponding update for Ubuntu 18.04 LTS. Original advisory details: Wenchao Li discovered that the Django Truncator function incorrectly handled very long HTML input. A remote attacker could possibly use this issue to cause Django to consume resources, leading to a denial of service. It was discovered that Django incorrectly handled certain URIs with a very large number of Unicode characters. A remote attacker could possibly use this issue to cause Django to consume resources or crash, leading to a denial of service.
Affected Software
Event History
Frequently Asked Questions
What vulnerabilities did USN-6414-2 fix?
USN-6414-2 fixed CVE-2023-43665 and CVE-2023-41164 in Django.
What is the severity of the vulnerabilities fixed by USN-6414-2?
The severity of the vulnerabilities fixed by USN-6414-2 is not specified.
How can I update Django on Ubuntu 18.04 LTS to fix the vulnerabilities?
To update Django on Ubuntu 18.04 LTS and fix the vulnerabilities, follow the instructions provided in the Ubuntu security notice USN-6414-2.
Where can I find more information about CVE-2023-43665?
You can find more information about CVE-2023-43665 in the Ubuntu security notice USN-6414-2.
Where can I find more information about CVE-2023-41164?
You can find more information about CVE-2023-41164 in the Ubuntu security notice USN-6414-2.