VDB
CVE-2007-5712
CVE-2007-5712
PUBLISHED
CVSS 2.5999999046325684 LOW
The internationalization (i18n) framework in Django 0.91, 0.95, 0.95.1, and 0.96, and as used in other products such as PyLucid, when the USE_I18N option and the i18n component are enabled, allows remote attackers to cause a denial of service (memory consumption) via many HTTP requests with large Accept-Language headers.
EPSS 1.81% · 76.6th percentile
Risk Scores
CVSS 2.0
2.5999999046325684
EPSS Score
1.81%
76.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| django_project | django | 0.95, 0.91, 0.96 |
| n/a | n/a | n/a |
| PyPI | Django | 0.91.0, 0.96.0, 0.91.0 |
Timeline
- Oct 30, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 31, 2023 EPSS Score
References
- FEDORA-2007-2788 vendor-advisory
- http://sourceforge.net/forum/forum.php?forum_id=749199 url
- django-i18n-dos(38143) vdb
- http://www.djangoproject.com/weblog/2007/oct/26/security-fix url
- ADV-2007-3660 vdb
- FEDORA-2007-3157 vendor-advisory
- DSA-1640 vendor-advisory
- 27435 third-party-advisory
- 26227 vdb
- 31961 third-party-advisory
- ADV-2007-3661 vdb
- 27597 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2007-5712 advisory
- https://github.com/django/django/commit/412ed22502e11c50dbfee854627594f0e7e2c234 url
- https://github.com/django/django/commit/7dd2dd08a79e388732ce00e2b5514f15bd6d0f6f url
- https://github.com/django/django/commit/8bc36e726c9e8c75c681d3ad232df8e882aaac81 url
- https://github.com/django/django package
- https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2007-1.yaml url
- https://web.archive.org/web/20091201070224/http://secunia.com/advisories/27435 url
- https://web.archive.org/web/20111224195100/http://secunia.com/advisories/27597 url
…and 2 more