The Vulnerability History Project
Vulnerabilities
Insights
Curate
Tags
All
Projects
CWEs
Languages
Lessons
Severities
Subsystems
More
News
Projects We Study
How to Contribute
By the Numbers
About Us
Toggle Theme
Warning: Our website does not support Internet Explorer, please use Edge instead.
[1.3.x] Restrict the XML deserializer to prevent network and entity-expansion DoS attacks.
This is a security fix. Disclosure and advisory coming shortly.
by
Lawrence the Dove 2013-02-12 04:54:53 UTC
commit d19a27066b2247102e65412aa66917aff0091112
Django
Fix
CVE-2013-1664
Fix
CVE-2013-1665
django/core/serializers/xml_serializer.py
+1
-93
tests/regressiontests/serializers_regress/tests.py
-15
expand_less