-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 19 Mar 2025 14:40:53 +0000 Source: python-django Architecture: source Version: 2:2.2.28-1~deb11u6 Distribution: bullseye-security Urgency: medium Maintainer: Debian Python Team <team+python@tracker.debian.org> Changed-By: Chris Lamb <lamby@debian.org> Closes: 1099682 Changes: python-django (2:2.2.28-1~deb11u6) bullseye-security; urgency=medium . * CVE-2025-26699: Prevent a potential denial-of-service in the wrap() method of the django.utils.text module. This method and wordwrap template filter were subject to a potential DoS attack when used with very long strings. (Closes: #1099682) Checksums-Sha1: fe19eaf3e1b23ba0190eae8f415769710bedd10c 2812 python-django_2.2.28-1~deb11u6.dsc 0661bddaeca016d84abc4c808c1c677cd7d4aa7b 9187543 python-django_2.2.28.orig.tar.gz 6847c1f8bd9358ae97eec197aa893bf9fbd55987 46600 python-django_2.2.28-1~deb11u6.debian.tar.xz a054cc8949e0de6727a437a75451952fd48f3295 14303 python-django_2.2.28-1~deb11u6_amd64.buildinfo Checksums-Sha256: d96eaa8cf665ece99131e5a922592406354b5cbc4ffcf3af9c35ffa6becd199a 2812 python-django_2.2.28-1~deb11u6.dsc 0200b657afbf1bc08003845ddda053c7641b9b24951e52acd51f6abda33a7413 9187543 python-django_2.2.28.orig.tar.gz 402c2a963281e62d83099f4bcfb119285d7d65f7a226752a72237ce0f19c633d 46600 python-django_2.2.28-1~deb11u6.debian.tar.xz ee790a4a0043b299928184bd34cbc8f3d380e7d3440240048bc17317c06418de 14303 python-django_2.2.28-1~deb11u6_amd64.buildinfo Files: 164f9a87ebfedb3151f057434ebfe2bc 2812 python optional python-django_2.2.28-1~deb11u6.dsc 62550f105ef66ac7d08e0126f457578a 9187543 python optional python-django_2.2.28.orig.tar.gz 0dca1e94c872bd722bfec0aee206b6a1 46600 python optional python-django_2.2.28-1~deb11u6.debian.tar.xz d6504f941b2e0c5072eb80bf06b31975 14303 python optional python-django_2.2.28-1~deb11u6_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmfa7K4ACgkQHpU+J9Qx HlgX2w//U5G8F+/CAd2VBd7gYSQXNnzeZjGk2/yC9pPIrwVUSNBACd7LWExHsenb On+LSbwxljh2we4TFyn7bqXHyZ0HgtGIr1AE43/T5w6f3HaYG+CgUY7OFTCqHnWc 3FlaRF67htEPJ7wfAtlJJU9hJevU0Dige89wmXoZJBNhJnBVmc9JrgtQmjz8rZmb DGhW9WXZHZjTKJdESZps03zVzg5KjgLCqpMv0ZEHTLIyay3pfKamuL+7RFIwShNs dVgi8X3oWl1Vb5V+Gd3TqxoXolsTsHWgZTUxOsVWKmB5xQJNSqNfLd2t02m975Dz i+XArZ7urmJK5GZqhzoei6AANkjo40aUaW31WwtwoMHdQhDWfQ8hOsfuAdXROAHq aruXzxsNpI2wXQ3K28NwdlAhZgNh4+OOFZC3j8s+cAHdWsz8gIUNj5AJi6oCMO8N KRPtDtLwp7kEXRgzzJjSmC7hteF209QqmWYYYNhu4L2jPsa/OrMyL3mzn02VtT/w XbeUI+Qqus8TFDZ+KDXVJAmPPxGURzwrz92jhUnizoyzaC45yr6AcUm4/7zPdJqn 8OhYSVl70+JxC7J8kIOrr5lHg/1IMX86ZeDuk8nNVOd4Fl8NxK+jSYCa/yh/xCvH c2X5a7CJnJl5wxxuZKKPZM3YXqh7KxDZTjBIBwF1A8CZBMOjjA8= =opmZ -----END PGP SIGNATURE-----