FlawAtlas
Search the atlas
SUSE-SU-2019:2042-1 Not scored

Security update for python-Django

This update for python-Django fixes the following issues: - Fixed CVE-2019-6975 (bsc#1124991) * Added CVE-2019-6975.patch to fix uncontrolled memory consumption * If ``django.utils.numberformat.format()`` -- used by ``contrib.admin`` as well as the the ``floatformat``, ``filesizeformat``, and ``intcomma`` templates filters -- received a ``Decimal`` with a large number of digits or a large exponent, it could lead to significant memory usage due to a call to ``'{:f}'.format()``. To avoid this, decimals with more than 200 digits are now formatted using scientific notation.

Exploit probability Not scored
Published August 2, 2019
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:OpenStack Cloud 7 python-Django

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2019:2042-1

This update for python-Django fixes the following issues: - Fixed CVE-2019-6975 (bsc#1124991) * Added CVE-2019-6975.patch to fix uncontrolled memory consumption * If ``django.utils.numberformat.format()`` -- used by ``contrib.admin`` as well as the the ``floatformat``, ``filesizeformat``, and ``intcomma`` templates filters -- received a ``Decimal`` with a large number of digits or a large exponent, it could lead to significant memory usage due to a call to ``'{:f}'.format()``. To avoid this, decimals with more than 200 digits are now formatted using scientific notation.

View original source

05 / REFERENCES

Further evidence