Debian Security Advisory

DLA-1629-1 python-django -- LTS security update

Date Reported:
06 Jan 2019
Affected Packages:
python-django
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2019-3498.
More information:

It was discovered that there was a content-spoofing vulnerability in the default 404 pages in the Django web development framework.

For more information, please see:

https://www.djangoproject.com/weblog/2019/jan/04/security-releases/

For Debian 8 Jessie, this issue has been fixed in python-django version 1.7.11-1+deb8u4.

We recommend that you upgrade your python-django packages.