The get_image_dimensions function in the image-handling functionality in Django before...
Vulnerability Description
The get_image_dimensions function in the image-handling functionality in Django before 1.3.2 and 1.4.x before 1.4.1 uses a constant chunk size in all attempts to determine dimensions, which allows remote attackers to cause a denial of service (process or thread consumption) via a large TIFF image.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-3444
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.openwall.com/lists/oss-security/2012/07/31/1
- https://www.djangoproject.com/weblog/2012/jul/30/security-releases-issued/
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:143
- http://www.ubuntu.com/usn/USN-1560-1
- http://www.openwall.com/lists/oss-security/2012/07/31/2
- http://www.debian.org/security/2012/dsa-2529
More from djangoproject
View All →Affected Vendor
djangoproject
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.