-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 02 Mar 2025 15:58:40 +0000 Source: python-django Architecture: source Version: 3:4.2.19-1~bpo12+1 Distribution: bookworm-backports Urgency: high Maintainer: Debian Python Team <team+python@tracker.debian.org> Changed-By: Colin Watson <cjwatson@debian.org> Closes: 1093049 Changes: python-django (3:4.2.19-1~bpo12+1) bookworm-backports; urgency=medium . * Rebuild for bookworm-backports. . python-django (3:4.2.19-1) unstable; urgency=medium . * New upstream bugfix release. <https://www.djangoproject.com/weblog/2025/feb/05/bugfix-releases/> . python-django (3:4.2.18-1) unstable; urgency=high . * New upstream security release. (Closes: #1093049) . - CVE-2024-56374: Potential denial-of-service vulnerability in IPv6 validation. . A lack of upper bound limit enforcement in strings passed when performing IPv6 validation could have led to a potential denial-of-service (DoS) attack. The undocumented and private functions clean_ipv6_address and is_valid_ipv6_address were vulnerable, as was the GenericIPAddressField form field, which has now been updated to define a max_length of 39 characters. The GenericIPAddressField model field was not affected. . <https://www.djangoproject.com/weblog/2025/jan/14/security-releases/> Checksums-Sha1: dbae5a53e994151f24d2e5f392fb2865fe13add6 2925 python-django_4.2.19-1~bpo12+1.dsc ae9242e08a672e60d8ded01e9c19c5b8920ec848 33444 python-django_4.2.19-1~bpo12+1.debian.tar.xz Checksums-Sha256: c5f8f13df50bef0cd3976fa8a1ec80b59e66cc50c1bd407a677b91990d3b70db 2925 python-django_4.2.19-1~bpo12+1.dsc defe1b014664191eeb139df830d1f219e43c6a251c758286412c943c4a539a77 33444 python-django_4.2.19-1~bpo12+1.debian.tar.xz Files: a202452cfcb8789655ee54578b4a067a 2925 python optional python-django_4.2.19-1~bpo12+1.dsc 31d124f7910886bbfd6118b18fa5b0e6 33444 python optional python-django_4.2.19-1~bpo12+1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEErApP8SYRtvzPAcEROTWH2X2GUAsFAmfEgnQACgkQOTWH2X2G UAuk2w/8CC5NhdKNYKgWZKR49wQOUn3jckL8jsRZX/2CDX/ziVvoSHylhzj55/Qy nFLanEMa9eqRGabM2NNZaunka+W+pPS/fqHDW9R0k5JVYFoBCQUu1mYETahnFSWx NqnxDZX9bZ29sCjdQ9rqYrEd+3Xp5HAaaQOBfupaPoX1ugG+8DDPISbauM31VXlP HD2qdAdAaaxuONYfvxKbeZ8QSpyeFLvZ4xTifqE+GAKgzZeJvak7KAPthYa1ypwW Za0/jZlDMW1qzaH5HRoBrjT/97lBrX5P3/ppc7OaNzLFz0LZlMlJSA9NFJrBDAj9 6f6U8EfY5XWI71XLkFqJ/5+rd81VMlS1xazD92nZIHBBM67tw3iZp4wxRD2ILX19 lKUYcERy1VqZOeMB6Wf1DeuHnV/iUXge3RbouZsp9esCPQLww0AV3iOfylJcSf30 fDRQIgHWtN5791WeRRu5dBAVM5l/7323P61HQvvUPmJiFXrogg0xSV0hG9vFPp6K LlC3klI+oKtScgKXWEP6WKNKvtTRmtu6wB8MhYE5HQE9JMF4Wnv065tHHK1NFO6H PTPAx31KdIDasSpMDXUPhP065FIEi4AqZvt++/0EHx9Pm71FANjsfcqWG1uHK3t5 iZKe1NUSa+KKU090tasZQrne+YbvOgZj5OaehDnl68MEVwc7x2E= =grYJ -----END PGP SIGNATURE-----