diff options
author | Peter Korsgaard <peter@korsgaard.com> | 2019-02-15 14:32:01 +0100 |
---|---|---|
committer | Thomas Petazzoni <thomas.petazzoni@bootlin.com> | 2019-02-15 21:48:38 +0100 |
commit | 653f86c0e91847dd8841837b650e2e966b59dd78 (patch) | |
tree | 8c2d18643b1dee2852d9fcdd141ec396e7bd9591 /package/libcpprestsdk/libcpprestsdk.mk | |
parent | 92f34e8fe297b740709a32aa49de58985783e95d (diff) | |
download | buildroot-653f86c0e91847dd8841837b650e2e966b59dd78.tar.gz buildroot-653f86c0e91847dd8841837b650e2e966b59dd78.zip |
package/python-django: security bump to version 2.1.7
Fixes the following security issues:
CVE-2019-6975: Memory exhaustion in django.utils.numberformat.format()
If django.utils.numberformat.format() – used by contrib.admin as well as the
the floatformat, filesizeformat, and intcomma templates filters – received a
Decimal with a large number of digits or a large exponent, it could lead to
significant memory usage due to a call to '{:f}'.format().
To avoid this, decimals with more than 200 digits are now formatted using
scientific notation.
https://docs.djangoproject.com/en/2.1/releases/2.1.6/
2.1.6 contained a packaging error, fixed by 2.1.7:
https://docs.djangoproject.com/en/2.1/releases/2.1.7/
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Diffstat (limited to 'package/libcpprestsdk/libcpprestsdk.mk')
0 files changed, 0 insertions, 0 deletions