PT-2012-4717 · Django · Django
Jeroen Dekkers
·
Published
2012-07-31
·
Updated
2022-05-17
·
CVE-2012-3444
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Django versions 1.3.x through 1.3.2
Django versions 1.4.x through 1.4.1
Description
The issue allows remote attackers to cause a denial of service, specifically process or thread consumption, via a large TIFF image. This is due to the
get image dimensions function using a constant chunk size in all attempts to determine dimensions.Recommendations
For Django versions 1.3.x through 1.3.2, update to version 1.3.2 or later.
For Django versions 1.4.x through 1.4.1, update to version 1.4.1 or later.
As a temporary workaround, consider restricting the upload of large TIFF images to minimize the risk of exploitation.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Django