CVE-2014-0481 Information
Feb 14, 2021
cve
Description
The default configuration for the file upload handling system in Django before 1.4.14 1.5.x before 1.5.9 1.6.x before 1.6.6 and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploaded which allows remote attackers to cause a denial of service (CPU consumption) by unloading a multiple files with the same name.
Reference
http://lists.opensuse.org/opensuse-updates/2014-09/msg00023.html http://secunia.com/advisories/59782 http://secunia.com/advisories/61276 http://secunia.com/advisories/61281 http://www.debian.org/security/2014/dsa-3010 https://www.djangoproject.com/weblog/2014/aug/20/security/
Share on: