USN-6946-1: Django vulnerabilities
It was discovered that Django incorrectly handled certain strings in floatformat function. An attacker could possibly use this issue to cause a memory exhaustion. (CVE-2024-41989) It was discovered that Django incorrectly handled very large inputs. An attacker could possibly use this issue to cause a denial of service. (CVE-2024-41990) It was discovered that Django in AdminURLFieldWidget incorrectly handled certain inputs with a very large number of Unicode characters. An attacker could possibly use this issue to cause a denial of service. (CVE-2024-41991) It was discovered that Django incorrectly handled certain JSON objects. An attacker could possibly use this issue to cause a potential SQL injection. This issue only affected Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-42005)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-6946-1?
The severity of USN-6946-1 is classified as critical due to its potential for memory exhaustion attacks.
How do I fix USN-6946-1?
To fix USN-6946-1, upgrade to the corrected Django package versions specified for your Ubuntu release.
Which versions of Django are affected by USN-6946-1?
USN-6946-1 affects various versions of Django including those prior to 4.2.11-1ubuntu1.2, 3.2.12-2ubuntu1.13, and 2.2.12-1ubuntu0.24.
What type of vulnerability is described in USN-6946-1?
USN-6946-1 describes a vulnerability in Django's floatformat function related to incorrect handling of strings and very large inputs.
Who is affected by the USN-6946-1 vulnerability?
Users running specified versions of Django on Ubuntu 18.04, 20.04, 22.04, and 24.04 are at risk from the USN-6946-1 vulnerability.