-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 05 Mar 2024 12:37:11 +0000 Source: python-django Built-For-Profiles: nocheck Architecture: source Version: 3:5.0.3-1 Distribution: experimental Urgency: medium Maintainer: Debian Python Team <team+python@tracker.debian.org> Changed-By: Chris Lamb <lamby@debian.org> Changes: python-django (3:5.0.3-1) experimental; urgency=medium . * New upstream security release: . - CVE-2024-27351: Fix a potential regular expression denial-of-service (ReDoS) attack in django.utils.text.Truncator.words. This method (with html=True) and the truncatewords_html template filter were subject to a potential regular expression denial-of-service attack via a suitably crafted string. This is, in part, a follow up to CVE-2019-14232 and CVE-2023-43665. . <https://docs.djangoproject.com/en/dev/releases/5.0.3/> Checksums-Sha1: 5559b5e11ee3770af488c0a3295e6579fe65aa22 2757 python-django_5.0.3-1.dsc 775c0c38e28724eaf43a9fedb3d996bd99b28dac 10620661 python-django_5.0.3.orig.tar.gz 19dea4d967da3145153c4344c1e5444c70f4494d 29132 python-django_5.0.3-1.debian.tar.xz a2391eefd2e171b0c2e45e7cad9fa8ba11337bf8 8068 python-django_5.0.3-1_amd64.buildinfo Checksums-Sha256: 804375eab56c9056ccbcfde2a4a0af2207c613caaabc89897bddbd5f0fbc633e 2757 python-django_5.0.3-1.dsc 5fb37580dcf4a262f9258c1f4373819aacca906431f505e4688e37f3a99195df 10620661 python-django_5.0.3.orig.tar.gz 73253b1c3cac8d95a2db651bcc95f9ff29d53c74b3ba5b5628d54c639d26400f 29132 python-django_5.0.3-1.debian.tar.xz 5b25d5a2f067a8bba386a2db6e7130b1859470cfcbc673405a60146edc2429f5 8068 python-django_5.0.3-1_amd64.buildinfo Files: b98d375bd8f8340dca4298d6ddf3a313 2757 python optional python-django_5.0.3-1.dsc 1009c48d70060cadb40000cc15a8058a 10620661 python optional python-django_5.0.3.orig.tar.gz 1dec61d13399232882c5be181efcd6ea 29132 python optional python-django_5.0.3-1.debian.tar.xz b5d3b3d6c7786cda23628d610554bc69 8068 python optional python-django_5.0.3-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmXnFUEACgkQHpU+J9Qx HlhfVA/9HLTOpBAlvXjjc6/W/Ln+BWRcqrCfDchxsc8XOer782IMfCUNNQjkIRCj SqV+EtAVdvG828AQ27qABYYVY0loOp+CeePNXsTiWxyxE6D+v7DQpQLR6n59egoF Oyt1vWi0i6fD6gm87Fbj58pQOwB4ww9tZIIIeeUuAnjwk30AdCeJkxT6FdNGwVDY FlxJpyg+ILu4LljY8BzrOHSx+5MBfeWqlZzT+9or4CGq4A++0cd1lEhFXsKIGfYx mb3HFBamd3xa1UGkqw11QrH4OXGV4pVwo9mCzeOdQEoLMKXUYOuADv1whg0nZbVV Sd5ei+Ou+xn6ucnUmUYT+23GLYm/RvRBZuZfEtyTVotQQIJNWsd9ZltVI0D8aeB6 b3aS4qFMyMMQxlcAkyS/Xtgw7Oj6ts+NrjjrRd6O/zLZbxalFhyg8w0ahgJ20q35 ZIp409uetsaH/x1GbJPuBbBmJkIy5XswtqUWN+6X8+JwnuTapWuaJays5pVTLHW5 XRJF/Ic/u3rMUaOLonRoJKSlAbGVJD6PSG0jA+kMbalGRje+b9TApCelUrNRG1pL QBKNnIdVDZT28PHxvUxsbP7zhAIrTNkQ9siSZ6kSnAJoBxt63c7ks6vxMdPo08aq QNPRd9jcoFfVv/pQmwqzCSP9FGicQk72Fl5CoGXxOOft5kogWqw= =62cO -----END PGP SIGNATURE-----