Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0481

Опубликовано: 26 авг. 2014
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3

Описание

The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploaded, which allows remote attackers to cause a denial of service (CPU consumption) by unloading a multiple files with the same name.

РелизСтатусПримечание
devel

not-affected

1.6.6-1
esm-infra-legacy/trusty

released

1.6.1-2ubuntu0.4
lucid

released

1.1.1-2ubuntu1.13
precise

released

1.3.1-4ubuntu1.12
trusty

released

1.6.1-2ubuntu0.4
trusty/esm

released

1.6.1-2ubuntu0.4
upstream

released

1.6.6-1

Показывать по

EPSS

Процентиль: 78%
0.01121
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
больше 11 лет назад

The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploaded, which allows remote attackers to cause a denial of service (CPU consumption) by unloading a multiple files with the same name.

nvd
больше 11 лет назад

The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploaded, which allows remote attackers to cause a denial of service (CPU consumption) by unloading a multiple files with the same name.

debian
больше 11 лет назад

The default configuration for the file upload handling system in Djang ...

CVSS3: 7.5
github
больше 3 лет назад

Django denial of service via file upload naming

EPSS

Процентиль: 78%
0.01121
Низкий

4.3 Medium

CVSS2