Path to this page:
Subject: CVS commit: pkgsrc/www/py-django
From: Adam Ciarcinski
Date: 2025-01-14 16:55:07
Message id: 20250114155508.002B4FC1D@cvs.NetBSD.org
Log Message:
py-django: updated to 5.1.5
Django 5.1.5 fixes a security issue with severity “moderate” and one bug in \
5.1.4.
CVE-2024-56374: Potential denial-of-service vulnerability in IPv6 validation
Lack of upper bound limit enforcement in strings passed when performing IPv6 \
validation could lead to a potential denial-of-service attack. The undocumented \
and private functions clean_ipv6_address and is_valid_ipv6_address were \
vulnerable, as was the django.forms.GenericIPAddressField form field, which has \
now been updated to define a max_length of 39 characters.
The django.db.models.GenericIPAddressField model field was not affected.
Bugfixes
Fixed a crash when applying migrations with references to the removed \
Meta.index_together option
Files: