Security Advisory

CVE-2014-0474

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2014-04-23 14:00:00
Last updated 2024-08-06 09:20:18
Assigner debian
State PUBLISHED

Description

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."