[ubuntu/questing-security] python-django 3:5.2.4-1ubuntu2.2 (Accepted)
Hlib Korzhynskyy
hlib.korzhynskyy at canonical.com
Tue Dec 2 14:57:39 UTC 2025
python-django (3:5.2.4-1ubuntu2.2) questing-security; urgency=medium
* SECURITY UPDATE: SQL injection in FilteredRelation column aliases on
PostgreSQL
- debian/patches/CVE-2025-13372.patch: protect FilteredRelation against
SQL injection in column aliases in
django/db/backends/postgresql/compiler.py,
tests/annotations/tests.py.
- CVE-2025-13372
* SECURITY UPDATE: DoS vulnerability in XML serializer text extraction
- debian/patches/CVE-2025-64460.patch: corrected quadratic inner text
accumulation in XML serializer in
django/core/serializers/xml_serializer.py,
docs/topics/serialization.txt,
tests/serializers/test_deserialization.py.
- CVE-2025-64460
Date: 2025-11-26 17:19:11.943798+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
https://launchpad.net/ubuntu/+source/python-django/3:5.2.4-1ubuntu2.2
-------------- next part --------------
Sorry, changesfile not available.
More information about the Questing-changes
mailing list