Fedora 20 : python-django-1.6.3-1.fc20 (2014-5503)

high Nessus Plugin ID 73812

Synopsis

The remote Fedora host is missing a security update.

Description

update to 1.6.3 fixing CVE-2014-0473 and CVE-2014-0474 update to 1.6.2 (rhbz#1027766)

Please note, it is required to update python-django and python3-django as well in one transaction. yum update or dnf update will do that for you.

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected python-django package.

See Also

https://bugzilla.redhat.com/show_bug.cgi?id=1027766

https://bugzilla.redhat.com/show_bug.cgi?id=1035987

https://bugzilla.redhat.com/show_bug.cgi?id=1073773

http://www.nessus.org/u?893b61bb

Plugin Details

Severity: High

ID: 73812

File Name: fedora_2014-5503.nasl

Version: 1.4

Type: local

Agent: unix

Published: 5/2/2014

Updated: 1/11/2021

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Vulnerability Information

CPE: cpe:/o:fedoraproject:fedora:20, p-cpe:/a:fedoraproject:fedora:python-django

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 4/23/2014

Reference Information

FEDORA: 2014-5503