CVE-2013-0306

Django 1.3.x < 1.3.6, 1.4.x < 1.4.4, 1.5 < RC2 - Denial of Service via Formset max_num Parameter

Title source: llm
STIX 2.1

Description

The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_num parameter.

References (4)

Core 4
Core References
Various Sources vendor-advisory x_refsource_ubuntu
http://ubuntu.com/usn/usn-1757-1
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2013/dsa-2634
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0670.html

Scores

EPSS 0.0257
EPSS Percentile 83.5%

Details

CWE
CWE-189
Status published
Products (13)
canonical/ubuntu_linux 10.04
canonical/ubuntu_linux 11.10
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 12.10
djangoproject/django 1.3 (3 CPE variants)
djangoproject/django 1.3.1
djangoproject/django 1.3.2
djangoproject/django 1.3.3
djangoproject/django 1.4 (3 CPE variants)
djangoproject/django 1.4.1
... and 3 more
Published May 02, 2013
Tracked Since Feb 18, 2026