CVE-2014-0472

Publication date 22 April 2014

Last updated 10 October 2025


Ubuntu priority

Description

The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leveraging a view that constructs URLs using user input and a "dotted Python path."

Status

Package Ubuntu Release Status
python-django 14.04 LTS trusty
Fixed 1.6.1-2ubuntu0.1
13.10 saucy
Fixed 1.5.4-1ubuntu1.1
12.10 quantal
Fixed 1.4.1-2ubuntu0.5
12.04 LTS precise
Fixed 1.3.1-4ubuntu1.9
10.04 LTS lucid
Fixed 1.1.1-2ubuntu1.10

References

Related Ubuntu Security Notices (USN)

Other references