Ubuntu Security Notice 1297-1 - Pall McMillan discovered that Django used the root namespace when storing cached session data. A remote attacker could exploit this to modify sessions. Paul McMillan discovered that Django would not timeout on arbitrary URLs when the application used URLFields. This could be exploited by a remote attacker to cause a denial of service via resource exhaustion. Various other issues were also addressed.
d90812dfe62d74192f723148eedd422416897927518969173061c4a5f2b9bc9c
Debian Linux Security Advisory 2332-1 - Paul McMillan, Mozilla and the Django core team discovered several vulnerabilities in Django, a Python web framework.
58a235a4d66e5650b14ae17e73287994e75b7e79c69339689b8b98c9c34b52a1