Comment 9 for bug 1311433

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package python-django - 1.1.1-2ubuntu1.11

---------------
python-django (1.1.1-2ubuntu1.11) lucid-security; urgency=medium

  * SECURITY REGRESSION: security fix regression when a view is a partial
    (LP: #1311433)
    - debian/patches/CVE-2014-0472-regression.patch: create the lookup_str
      from the original function whenever a partial is provided as an
      argument to a url pattern in django/core/urlresolvers.py,
      added tests to tests/regressiontests/urlpatterns_reverse/urls.py,
      tests/regressiontests/urlpatterns_reverse/views.py.
    - CVE-2014-0472
 -- Marc Deslauriers <email address hidden> Tue, 22 Apr 2014 23:20:22 -0400