Collected research
James Bennett -- Django DOS
Patches for Django Framework Fix DoS Vulnerability
Django hashed submitted passwords with no length cap, so repeatedly posting very large passwords tied servers up in PBKDF2 work - about a minute for a one-megabyte password. Releases 1.4.8, 1.5.4 and 1.6 beta 4 reject authentication above 4096 bytes (CVE-2013-1443). The flaw was disclosed publicly on the developers' mailing list, forcing an out-of-band release.
Record
- Document
- Patches for Django Framework Fix DoS Vulnerability
- Researcher
- Chris Brook
- Published by
- Threatpost | The first stop for security news
- Date
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Chris Brook, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .