SUSE-SU-2016:0044-1: moderate: Security update for python-Django

sle-updates at lists.suse.com sle-updates at lists.suse.com
Thu Jan 7 07:11:54 MST 2016


   SUSE Security Update: Security update for python-Django
______________________________________________________________________________

Announcement ID:    SUSE-SU-2016:0044-1
Rating:             moderate
References:         #937522 #937523 #941587 #955412 
Cross-References:   CVE-2015-5143 CVE-2015-5144 CVE-2015-5963
                    CVE-2015-8213
Affected Products:
                    SUSE Enterprise Storage 2
______________________________________________________________________________

   An update that fixes four vulnerabilities is now available.

Description:



   This update fixes the following security issues:


   - (bnc#955412, CVE-2015-8213) Possible settings leak in date template
     filter

   - (bnc#937522, CVE-2015-5143) Possible denial-of-service in session store

   - (bnc#937523, CVE-2015-5144) Possible Header injection

   - (bnc#941587, CVE-2015-5963) Possible denial-of-service by filling
     session store via logout()


Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Enterprise Storage 2:

      zypper in -t patch SUSE-Storage-2-2016-35=1

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Enterprise Storage 2 (noarch):

      python-Django-1.6.11-3.1


References:

   https://www.suse.com/security/cve/CVE-2015-5143.html
   https://www.suse.com/security/cve/CVE-2015-5144.html
   https://www.suse.com/security/cve/CVE-2015-5963.html
   https://www.suse.com/security/cve/CVE-2015-8213.html
   https://bugzilla.suse.com/937522
   https://bugzilla.suse.com/937523
   https://bugzilla.suse.com/941587
   https://bugzilla.suse.com/955412



More information about the sle-updates mailing list