Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-4535

Опубликовано: 10 янв. 2011
Источник: ubuntu
Приоритет: medium
CVSS2: 5

Описание

The password reset functionality in django.contrib.auth in Django before 1.1.3, 1.2.x before 1.2.4, and 1.3.x before 1.3 beta 1 does not validate the length of a string representing a base36 timestamp, which allows remote attackers to cause a denial of service (resource consumption) via a URL that specifies a large base36 integer.

РелизСтатусПримечание
dapper

DNE

devel

released

1.2.3-1ubuntu0.2.11.04.1
hardy

ignored

end of life
karmic

released

1.1.1-1ubuntu1.1
lucid

released

1.1.1-2ubuntu1.2
maverick

released

1.2.3-1ubuntu0.2.10.10.1
natty

released

1.2.3-1ubuntu0.2.11.04.1
oneiric

released

1.2.3-1ubuntu0.2.11.04.1
upstream

released

1.2.4-1

Показывать по

5 Medium

CVSS2

Связанные уязвимости

nvd
больше 14 лет назад

The password reset functionality in django.contrib.auth in Django before 1.1.3, 1.2.x before 1.2.4, and 1.3.x before 1.3 beta 1 does not validate the length of a string representing a base36 timestamp, which allows remote attackers to cause a denial of service (resource consumption) via a URL that specifies a large base36 integer.

debian
больше 14 лет назад

The password reset functionality in django.contrib.auth in Django befo ...

CVSS3: 7.5
github
почти 7 лет назад

Improper date handling in Django

5 Medium

CVSS2