Path to this page:
Subject: CVS commit: pkgsrc/www/py-django
From: Adam Ciarcinski
Date: 2019-02-12 14:11:56
Message id: 20190212131156.BB516FB16@cvs.NetBSD.org
Log Message:
py-django: updated to 1.11.20
1.11.20:
Bugfixes
Corrected packaging error from 1.11.19
1.11.19:
CVE-2019-6975: Memory exhaustion in django.utils.numberformat.format()
If django.utils.numberformat.format() – used by contrib.admin as well as the \
the floatformat, filesizeformat, and intcomma templates filters – received a \
Decimal with a large number of digits or a large exponent, it could lead to \
significant memory usage due to a call to '{:f}'.format().
To avoid this, decimals with more than 200 digits are now formatted using \
scientific notation.
Files: