summaryrefslogtreecommitdiffstats
path: root/package/python-django/python-django.hash
diff options
context:
space:
mode:
authorGustavo Zacarias <gustavo@zacarias.com.ar>2015-01-14 15:21:44 -0300
committerThomas Petazzoni <thomas.petazzoni@free-electrons.com>2015-01-14 19:26:12 +0100
commit23ed2cf2dc85f98412862c66766f9aaeee23621e (patch)
tree14cdbda598576dc1f75a00d519fae1edb9fe6805 /package/python-django/python-django.hash
parent6952e32f37ea58e3861f89fc687c230c3d4742d1 (diff)
downloadbuildroot-23ed2cf2dc85f98412862c66766f9aaeee23621e.tar.gz
buildroot-23ed2cf2dc85f98412862c66766f9aaeee23621e.zip
python-django: security bump to version 1.7.3
Fixes: CVE-2015-0219 - incorrectly handled underscores in WSGI headers. A remote attacker could possibly use this issue to spoof headers in certain environments. CVE-2015-0220 - incorrectly handled user-supplied redirect URLs. A remote attacker could possibly use this issue to perform a cross-site scripting attack. CVE-2015-0221 - incorrectly handled reading files in django.views.static.serve(). A remote attacker could possibly use this issue to cause Django to consume resources, resulting in a denial of service. CVE-2015-0222 - incorrectly handled forms with ModelMultipleChoiceField. A remote attacker could possibly use this issue to cause a large number of SQL queries, resulting in a database denial of service. Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar> Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
Diffstat (limited to 'package/python-django/python-django.hash')
-rw-r--r--package/python-django/python-django.hash4
1 files changed, 2 insertions, 2 deletions
diff --git a/package/python-django/python-django.hash b/package/python-django/python-django.hash
index 0195a13b05..f51c9b4741 100644
--- a/package/python-django/python-django.hash
+++ b/package/python-django/python-django.hash
@@ -1,2 +1,2 @@
-# sha256 from https://www.djangoproject.com/m/pgp/Django-1.7.2.checksum.txt
-sha256 31c6c3c229f8c04b3be87e6afc3492903b57ec8f1188a47b6ae160d90cf653c8 Django-1.7.2.tar.gz
+# sha256 from https://www.djangoproject.com/m/pgp/Django-1.7.3.checksum.txt
+sha256 f226fb8aa438456968d403f6739de1cf2dad128db86f66ee2b41dfebe3645c5b Django-1.7.3.tar.gz
OpenPOWER on IntegriCloud