CVE-2014-0474 Information
Feb 14, 2021
cve
Description
The (1) FilePathField (2) GenericIPAddressField and (3) IPAddressField model field classes in Django before 1.4.11 1.5.x before 1.5.6 1.6.x before 1.6.3 and 1.7.x before 1.7 beta 2 do not properly perform type conversion which allows remote attackers to have unspecified impact and vectors related to \MySQL typecasting.\
Reference
http://lists.opensuse.org/opensuse-updates/2014-09/msg00023.html http://rhn.redhat.com/errata/RHSA-2014-0456.html http://rhn.redhat.com/errata/RHSA-2014-0457.html http://secunia.com/advisories/61281 http://www.debian.org/security/2014/dsa-2934 http://www.ubuntu.com/usn/USN-2169-1 https://www.djangoproject.com/weblog/2014/apr/21/security/
Share on: