Hide Forgot
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-0474 to the following vulnerability: Name: CVE-2014-0474 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0474 Assigned: 20131219 Reference: https://www.djangoproject.com/weblog/2014/apr/21/security/ The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."
This has been addressed in Fedora 20 and EPEL6: https://admin.fedoraproject.org/updates/Django14-1.4.11-1.el6 https://admin.fedoraproject.org/updates/python-django15-1.5.6-1.fc20 https://admin.fedoraproject.org/updates/python-django14-1.4.11-1.fc20 https://admin.fedoraproject.org/updates/python-django-1.6.3-1.fc20
Acknowledgements: Red Hat would like to thank the upstream Django project for reporting this issue. Upstream acknowledges the Ruby on Rails team, and specifically Michael Koziarski, as the original reporters.
This issue has been addressed in following products: OpenStack 3 for RHEL 6 Via RHSA-2014:0457 https://rhn.redhat.com/errata/RHSA-2014-0457.html
This issue has been addressed in following products: OpenStack 4 for RHEL 6 Via RHSA-2014:0456 https://rhn.redhat.com/errata/RHSA-2014-0456.html