Bug 13384 - python-django new security issues CVE-2014-1418 and CVE-2014-3730
Summary: python-django new security issues CVE-2014-1418 and CVE-2014-3730
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 4
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/598863/
Whiteboard: MGA3TOO has_procedure advisory mga3-3...
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2014-05-15 16:11 CEST by David Walser
Modified: 2014-05-20 19:02 CEST (History)
4 users (show)

See Also:
Source RPM: python-django-1.6.3-2.mga5.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2014-05-15 16:11:44 CEST
Upstream has issued an advisory on May 14:
https://www.djangoproject.com/weblog/2014/may/14/security-releases-issued/

The issues are fixed upstream in 1.4.13, 1.5.8, and 1.6.5.

Mageia 3 and Mageia 4 are also affected.

Reproducible: 

Steps to Reproduce:
David Walser 2014-05-15 16:11:50 CEST

Whiteboard: (none) => MGA4TOO, MGA3TOO

Comment 1 Oden Eriksson 2014-05-15 17:56:23 CEST
fixed with python-django-1.4.13-1.mga3, python-django-1.5.8-1.mga4 & python-django-1.5.8-1.mga4.

CC: (none) => oe

Comment 2 David Walser 2014-05-15 18:17:08 CEST
Thanks Oden!  Unfortunately we currently have multiple Django versions packaged, so there's also a python-django14 SRPM in Mageia 4 and Cauldron which need to be updated as well.
Comment 3 David Walser 2014-05-15 18:30:47 CEST
Ubuntu has issued an advisory for this on May 14:
http://www.ubuntu.com/usn/usn-2212-1/

URL: (none) => http://lwn.net/Vulnerabilities/598863/

Comment 4 Philippe Makowski 2014-05-15 22:37:36 CEST
fixed too in python-django14-1.4.13-1.mga4 and python-django14-1.4.13-2.mga5
Comment 5 David Walser 2014-05-16 17:10:42 CEST
Thanks Philippe (and Oden)!

Advisory:
========================

Updated python-django and python-dgango14 packages fix security vulnerabilities:

Stephen Stewart, Michael Nelson, Natalia Bidart and James Westby
discovered that Django improperly removed Vary and Cache-Control headers
from HTTP responses when replying to a request from an Internet Explorer
or Chrome Frame client. An attacker may use this to retrieve private data
or poison caches. This update removes workarounds for bugs in Internet
Explorer 6 and 7 (CVE-2014-1418).

Peter Kuma and Gavin Wahl discovered that Django did not correctly
validate some malformed URLs, which are accepted by some browsers. An
attacker may use this to cause unexpected redirects (CVE-2014-3730).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1418
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3730
https://www.djangoproject.com/weblog/2014/may/14/security-releases-issued/
http://www.ubuntu.com/usn/usn-2212-1/
========================

Updated packages in core/updates_testing:
========================
python-django-1.4.13-1.mga3
python-django-1.5.8-1.mga4
python3-django-1.5.8-1.mga4
python-django-doc-1.5.8-1.mga4
python-django14-1.4.13-1.mga4

from SRPMS:
python-django-1.4.13-1.mga3.src.rpm
python-django-1.5.8-1.mga4.src.rpm
python-django14-1.4.13-1.mga4.src.rpm

CC: (none) => makowski.mageia
Version: Cauldron => 4
Assignee: makowski.mageia => qa-bugs
Whiteboard: MGA4TOO, MGA3TOO => MGA3TOO

Comment 6 claire robinson 2014-05-16 17:44:04 CEST
Procedure: https://bugs.mageia.org/show_bug.cgi?id=13251#c6

Whiteboard: MGA3TOO => MGA3TOO has_procedure

Comment 7 Philippe Makowski 2014-05-16 20:06:30 CEST
test ok on mga3-64

Whiteboard: MGA3TOO has_procedure => MGA3TOO has_procedure mga3-64-ok

Comment 8 Philippe Makowski 2014-05-16 21:38:20 CEST
test ok on mga4-64

Whiteboard: MGA3TOO has_procedure mga3-64-ok => MGA3TOO has_procedure mga3-64-ok mga4-64-ok

Comment 9 claire robinson 2014-05-19 17:27:23 CEST
Testing complete mga3 32

Whiteboard: MGA3TOO has_procedure mga3-64-ok mga4-64-ok => MGA3TOO has_procedure mga3-32-ok mga3-64-ok mga4-64-ok

Comment 10 claire robinson 2014-05-19 17:53:19 CEST
Testing complete mga4 32

Whiteboard: MGA3TOO has_procedure mga3-32-ok mga3-64-ok mga4-64-ok => MGA3TOO has_procedure mga3-32-ok mga3-64-ok mga4-32-ok mga4-64-ok

Comment 11 claire robinson 2014-05-19 17:57:59 CEST
Advisory uploaded. Validating.

Could sysadmin please push to 3 & 4 updates

Thanks
claire robinson 2014-05-19 17:58:12 CEST

Keywords: (none) => validated_update
Whiteboard: MGA3TOO has_procedure mga3-32-ok mga3-64-ok mga4-32-ok mga4-64-ok => MGA3TOO has_procedure advisory mga3-32-ok mga3-64-ok mga4-32-ok mga4-64-ok
CC: (none) => sysadmin-bugs

Comment 12 Thomas Backlund 2014-05-19 21:07:22 CEST
Update pushed:
http://advisories.mageia.org/MGASA-2014-0231.html

Status: NEW => RESOLVED
CC: (none) => tmb
Resolution: (none) => FIXED

Comment 13 David Walser 2014-05-20 19:02:09 CEST
LWN reference for CVE-2014-3730:
http://lwn.net/Vulnerabilities/599626/

Note You need to log in before you can comment on or make changes to this bug.