Description
The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_num parameter.
CVSS vector
AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9Complexity: Low
Confidentiality: None
Integrity: None
Affected Packages2 packages
Also affects: Ubuntu Linux 10.04, 11.10, 12.04, 12.10
🔴Vulnerability Details
4OSVDjango is vulnerable to Denial of Service attack in formset↗2022-05-05 ▶ GHSADjango is vulnerable to Denial of Service attack in formset↗2022-05-05 ▶ OSVCVE-2013-0306: The form library in Django 1↗2013-05-02 ▶ CVEListCVE-2013-0306: The form library in Django 1↗2013-05-02 ▶ 📋Vendor Advisories
3UbuntuDjango vulnerabilities↗2013-03-07 ▶ Red HatDjango: Formset denial-of-service↗2013-02-19 ▶ DebianCVE-2013-0306: python-django - The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 befor...↗2013 ▶ 💬Community
5BugzillaCVE-2013-0306 Django: Formset denial-of-service↗2013-02-20 ▶ BugzillaCVE-2013-0305 CVE-2013-0306 Django various flaws [epel-5]↗2013-02-20 ▶ BugzillaCVE-2013-0305 CVE-2013-0306 Django14 various flaws [epel-6]↗2013-02-20 ▶ BugzillaCVE-2013-0305 CVE-2013-0306 Django various flaws [fedora-17]↗2013-02-20 ▶ BugzillaCVE-2013-0305 CVE-2013-0306 Django various flaws [epel-6]↗2013-02-20 ▶