Upstream has issued an advisory today (January 4): https://www.djangoproject.com/weblog/2019/jan/04/security-releases/ The issue is fixed upstream in 1.1.18. As with Bug 23377, I don't know if Mageia 6 is affected, as 1.8.x is no longer supported. Hopefully Ubuntu or someone will be able to determine that again.
Assignee: bugsquad => pythonCC: (none) => makowski.mageia, marja11, smelror
Version 1.11.18 pushed to Cauldron.
It sounds like 1.8.x is affected from a comment on the Debian bug for this, so we would have to backport this patch: https://github.com/django/django/commit/1cd00fcf52d089ef0fe03beabd05d59df8ea052a
Version: Cauldron => 6
Advisory ======== An upstream patch has been backported to fix a security vulnerability in python-django. CVE-2019-3498: Content spoofing possibility in the default 404 page An attacker could craft a malicious URL that could make spoofed content appear on the default page generated by the django.views.defaults.page_not_found() view. The URL path is no longer displayed in the default 404 template and the request_path context variable is now quoted to fix the issue for custom templates that use the path. References ========== https://www.djangoproject.com/weblog/2019/jan/04/security-releases/ https://security-tracker.debian.org/tracker/CVE-2019-3498 Files ===== Uploaded to core/updates_testing python-django-1.8.19-1.1.mga6 python-django-bash-completion-1.8.19-1.1.mga6 python3-django-1.8.19-1.1.mga6 python-django-doc-1.8.19-1.1.mga6 from python-django-1.8.19-1.1.mga6.src.rpm
Assignee: python => qa-bugs
MGA6-32 MATE on IBM Thinkpad R50e No installation issues Ref to bug 17860 Comment 7 for testing Got exactly the same results as described in there, no point in repeating it all here (python and python3). OK for me.
CC: (none) => herman.viaeneWhiteboard: (none) => MGA6-32-OK
Thank you Herman. Pushing this on.
Keywords: (none) => advisory, validated_updateCC: (none) => lewyssmith, sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2019-0035.html
Resolution: (none) => FIXEDStatus: NEW => RESOLVED
Blocks: (none) => 24173