CVE-2013-0306
Django 1.3.x < 1.3.6, 1.4.x < 1.4.4, 1.5 < RC2 - Denial of Service via Formset max_num Parameter
Title source: llmDescription
The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_num parameter.
References (4)
Core 4
Core References
Vendor Advisory x_refsource_confirm
https://www.djangoproject.com/weblog/2013/feb/19/security/
Various Sources vendor-advisory
x_refsource_ubuntu
http://ubuntu.com/usn/usn-1757-1
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2013/dsa-2634
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0670.html
Scores
EPSS
0.0257
EPSS Percentile
83.5%
Details
CWE
CWE-189
Status
published
Products (13)
canonical/ubuntu_linux
10.04
canonical/ubuntu_linux
11.10
canonical/ubuntu_linux
12.04
canonical/ubuntu_linux
12.10
djangoproject/django
1.3 (3 CPE variants)
djangoproject/django
1.3.1
djangoproject/django
1.3.2
djangoproject/django
1.3.3
djangoproject/django
1.4 (3 CPE variants)
djangoproject/django
1.4.1
... and 3 more
Published
May 02, 2013
Tracked Since
Feb 18, 2026