apticron report [Sat, 09 Apr 2016 10:48:19 +0200]
========================================================================
apticron has detected that some packages need upgrading on:
hexagon.federez.net
[ 5.39.82.35 2001:41d0:8:9423::1 5.39.82.35 2001:41d0:8:9423::1 ]
The following packages are currently pending an upgrade:
python-django 1.7.7-1+deb8u4
python-django-common 1.7.7-1+deb8u4
========================================================================
Package Details:
Lecture des fichiers de modifications (« changelog »)...
--- Modifications pour python-django (python-django python-django-common) ---
python-django (1.7.7-1+deb8u4) jessie-security; urgency=high
* Non-maintainer upload by the Security Team.
* CVE-2016-2512: Prevented spoofing is_safe_url() with basic auth.
Malicious redirect and possible XSS attack via user-supplied redirect
URLs containing basic auth. (Closes: #816434)
* is_safe_url() crashes with a byestring URL on Python 2.
Fixes a regression introduced by the original fix for CVE-2016-2512.
* CVE-2016-2513: Fixed user enumeration timing attack during login
(Closes: #816434)
* Add Build-Depends on python-mock and python3-mock
-- Salvatore Bonaccorso <carnil(a)debian.org> Sat, 12 Mar 2016 17:13:01 +0100
========================================================================
You can perform the upgrade by issuing the command:
apt-get dist-upgrade
as root on hexagon.federez.net
--
apticron
apticron report [Fri, 08 Apr 2016 10:48:20 +0200]
========================================================================
apticron has detected that some packages need upgrading on:
hexagon.federez.net
[ 5.39.82.35 2001:41d0:8:9423::1 5.39.82.35 2001:41d0:8:9423::1 ]
The following packages are currently pending an upgrade:
python-django 1.7.7-1+deb8u4
python-django-common 1.7.7-1+deb8u4
========================================================================
Package Details:
Lecture des fichiers de modifications (« changelog »)...
--- Modifications pour python-django (python-django python-django-common) ---
python-django (1.7.7-1+deb8u4) jessie-security; urgency=high
* Non-maintainer upload by the Security Team.
* CVE-2016-2512: Prevented spoofing is_safe_url() with basic auth.
Malicious redirect and possible XSS attack via user-supplied redirect
URLs containing basic auth. (Closes: #816434)
* is_safe_url() crashes with a byestring URL on Python 2.
Fixes a regression introduced by the original fix for CVE-2016-2512.
* CVE-2016-2513: Fixed user enumeration timing attack during login
(Closes: #816434)
* Add Build-Depends on python-mock and python3-mock
-- Salvatore Bonaccorso <carnil(a)debian.org> Sat, 12 Mar 2016 17:13:01 +0100
========================================================================
You can perform the upgrade by issuing the command:
apt-get dist-upgrade
as root on hexagon.federez.net
--
apticron