Vulnerability Name: | CVE-2007-5712 (CCN-38143) | ||||||||||||||||
Assigned: | 2007-10-26 | ||||||||||||||||
Published: | 2007-10-26 | ||||||||||||||||
Updated: | 2017-07-29 | ||||||||||||||||
Summary: | The internationalization (i18n) framework in Django 0.91, 0.95, 0.95.1, and 0.96, and as used in other products such as PyLucid, when the USE_I18N option and the i18n component are enabled, allows remote attackers to cause a denial of service (memory consumption) via many HTTP requests with large Accept-Language headers. | ||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P) 1.9 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-399 | ||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2007-5712 Source: CCN Type: SA27435 Django "i18n" Denial of Service Vulnerability Source: SECUNIA Type: Patch, Vendor Advisory 27435 Source: SECUNIA Type: Vendor Advisory 27597 Source: SECUNIA Type: Vendor Advisory 31961 Source: CONFIRM Type: UNKNOWN http://sourceforge.net/forum/forum.php?forum_id=749199 Source: DEBIAN Type: Patch DSA-1640 Source: DEBIAN Type: DSA-1640 python-django -- several vulnerabilities Source: CCN Type: Django Web site Django Source: CONFIRM Type: Patch http://www.djangoproject.com/weblog/2007/oct/26/security-fix Source: CCN Type: OSVDB ID: 38905 Django Internationalization Framework USE_I18N Option Multiple HTTP Request Remote DoS Source: BID Type: UNKNOWN 26227 Source: CCN Type: BID-26227 Django i18n Remote Denial Of Service Vulnerability Source: VUPEN Type: Vendor Advisory ADV-2007-3660 Source: VUPEN Type: Vendor Advisory ADV-2007-3661 Source: XF Type: UNKNOWN django-i18n-dos(38143) Source: XF Type: UNKNOWN django-i18n-dos(38143) Source: FEDORA Type: UNKNOWN FEDORA-2007-2788 Source: FEDORA Type: UNKNOWN FEDORA-2007-3157 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |