CVE-2011-4137
Summary
| CVE | CVE-2011-4137 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-10-19 10:55:04 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The verify_exists functionality in the URLField implementation in Django before 1.2.7 and 1.3.x before 1.3.1 relies on Python libraries that attempt access to an arbitrary URL with no timeout, which allows remote attackers to cause a denial of service (resource consumption) via a URL associated with (1) a slow response, (2) a completed TCP connection with no application data sent, or (3) a large amount of application data, a related issue to CVE-2011-1521. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Djangoproject | Django | 0.91 | All | All | All |
| Application | Djangoproject | Django | 0.95 | All | All | All |
| Application | Djangoproject | Django | 0.95.1 | All | All | All |
| Application | Djangoproject | Django | 0.96 | All | All | All |
| Application | Djangoproject | Django | 1.0 | All | All | All |
| Application | Djangoproject | Django | 1.0.1 | All | All | All |
| Application | Djangoproject | Django | 1.0.2 | All | All | All |
| Application | Djangoproject | Django | 1.1 | All | All | All |
| Application | Djangoproject | Django | 1.1.0 | All | All | All |
| Application | Djangoproject | Django | 1.1.2 | All | All | All |
| Application | Djangoproject | Django | 1.1.3 | All | All | All |
| Application | Djangoproject | Django | 1.2 | All | All | All |
| Application | Djangoproject | Django | 1.2.1 | All | All | All |
| Application | Djangoproject | Django | 1.2.1 | 2 | All | All |
| Application | Djangoproject | Django | 1.2.2 | All | All | All |
| Application | Djangoproject | Django | 1.2.3 | All | All | All |
| Application | Djangoproject | Django | 1.2.4 | All | All | All |
| Application | Djangoproject | Django | 1.2.5 | All | All | All |
| Application | Djangoproject | Django | 1.3 | All | All | All |
| Application | Djangoproject | Django | 1.3 | alpha1 | All | All |
| Application | Djangoproject | Django | 1.3 | alpha2 | All | All |
| Application | Djangoproject | Django | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| September 9 | Weblog | Django | af854a3a-2127-422b-91ae-364da2661108 | www.djangoproject.com | Patch, Vendor Advisory |
| Bug 737366 – CVE-2011-4136 CVE-2011-4137 CVE-2011-4138 CVE-2011-4139 CVE-2011-4140 Django: v1.3.1, v1.2.7 multiple security flaws | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Patch |
| Security Advisory SA46614 - Debian update for python-django - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| oss-security - CVE Request -- Django: v1.3.1, v1.2.7 multiple security flaws | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Patch |
| hermes.opensuse.org/messages/14700881 | af854a3a-2127-422b-91ae-364da2661108 | hermes.opensuse.org | |
| Django | Weblog | Django 1.2.7 released | af854a3a-2127-422b-91ae-364da2661108 | www.djangoproject.com | Patch |
| Debian -- Security Information -- DSA-2332-1 python-django | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| oss-security - Re: CVE Request -- Django: v1.3.1, v1.2.7 multiple security flaws | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Patch |
| oss-security - Re: CVE Request -- Django: v1.3.1, v1.2.7 multiple security flaws | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981362 Python (pip) Security Update for django (GHSA-3jqw-crqj-w8qw)