Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0481

Опубликовано: 26 авг. 2014
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3

Описание

The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploaded, which allows remote attackers to cause a denial of service (CPU consumption) by unloading a multiple files with the same name.

РелизСтатусПримечание
devel

not-affected

1.6.6-1
esm-infra-legacy/trusty

not-affected

1.6.1-2ubuntu0.4
lucid

released

1.1.1-2ubuntu1.13
precise

released

1.3.1-4ubuntu1.12
trusty

released

1.6.1-2ubuntu0.4
trusty/esm

not-affected

1.6.1-2ubuntu0.4
upstream

released

1.6.6-1

Показывать по

EPSS

Процентиль: 80%
0.01487
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
почти 11 лет назад

The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploaded, which allows remote attackers to cause a denial of service (CPU consumption) by unloading a multiple files with the same name.

nvd
почти 11 лет назад

The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploaded, which allows remote attackers to cause a denial of service (CPU consumption) by unloading a multiple files with the same name.

debian
почти 11 лет назад

The default configuration for the file upload handling system in Djang ...

CVSS3: 7.5
github
около 3 лет назад

Django denial of service via file upload naming

EPSS

Процентиль: 80%
0.01487
Низкий

4.3 Medium

CVSS2