Subject: CVS commit: pkgsrc/www/py-django
From: Adam Ciarcinski
Date: 2025-01-14 16:55:07
Message id: 20250114155508.002B4FC1D@cvs.NetBSD.org

Log Message:
py-django: updated to 5.1.5

Django 5.1.5 fixes a security issue with severity “moderate” and one bug in \ 
5.1.4.

CVE-2024-56374: Potential denial-of-service vulnerability in IPv6 validation

Lack of upper bound limit enforcement in strings passed when performing IPv6 \ 
validation could lead to a potential denial-of-service attack. The undocumented \ 
and private functions clean_ipv6_address and is_valid_ipv6_address were \ 
vulnerable, as was the django.forms.GenericIPAddressField form field, which has \ 
now been updated to define a max_length of 39 characters.

The django.db.models.GenericIPAddressField model field was not affected.

Bugfixes

Fixed a crash when applying migrations with references to the removed \ 
Meta.index_together option

Files:
RevisionActionfile
1.138modifypkgsrc/www/py-django/Makefile
1.112modifypkgsrc/www/py-django/distinfo