Subject: CVS commit: pkgsrc/www/py-django4
From: Adam Ciarcinski
Date: 2025-01-14 16:56:01
Message id: 20250114155601.4952DFC1D@cvs.NetBSD.org

Log Message:
py-django4: updated to 4.2.18

Django 4.2.18 fixes a security issue with severity “moderate” in 4.2.17.

CVE-2024-56374: Potential denial-of-service vulnerability in IPv6 validation

Lack of upper bound limit enforcement in strings passed when performing IPv6 \ 
validation could lead to a potential denial-of-service attack. The undocumented \ 
and private functions clean_ipv6_address and is_valid_ipv6_address were \ 
vulnerable, as was the django.forms.GenericIPAddressField form field, which has \ 
now been updated to define a max_length of 39 characters.

The django.db.models.GenericIPAddressField model field was not affected.

Files:
RevisionActionfile
1.11modifypkgsrc/www/py-django4/Makefile
1.9modifypkgsrc/www/py-django4/distinfo