PT-2009-5954 · Django Software Foundation · Django

Steven M. Christey

·

Published

2009-10-13

·

Updated

2022-05-02

·

CVE-2009-3695

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Django versions 1.0 through 1.0.3 Django versions 1.1 through 1.1.0
Description The issue allows remote attackers to cause a denial of service, specifically CPU consumption, by providing a crafted input to either the EmailField (email address) or URLField (URL) that triggers excessive backtracking in a regular expression.
Recommendations For Django versions 1.0 through 1.0.3, update to version 1.0.4 or later. For Django versions 1.1 through 1.1.0, update to version 1.1.1 or later.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-3695
DSA-1905-1
GHSA-P6M5-H7PP-V2X5
PYSEC-2009-4

Affected Products

Django