https://bugzilla.redhat.com/show_bug.cgi?id=2314486
Bug ID: 2314486
Summary: CVE-2024-45230 python-django3: Potential
denial-of-service vulnerability in
django.utils.html.urlize() [epel-all]
Product: Fedora EPEL
Version: epel8
Status: NEW
Whiteboard: {"flaws": ["4fdc933a-92b1-4da5-856a-07a95761c0fb"]}
Component: python-django3
Keywords: Security, SecurityTracking
Severity: medium
Priority: medium
Assignee: michel(a)michel-slm.name
Reporter: mbenatto(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
michel(a)michel-slm.name
Blocks: 2314485 (CVE-2024-45230)
Target Milestone: ---
Classification: Fedora
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2314485
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
Referenced Bugs:
https://bugzilla.redhat.com/show_bug.cgi?id=2314485
[Bug 2314485] CVE-2024-45230 python-django: Potential denial-of-service
vulnerability in django.utils.html.urlize()
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2314486
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2393800
Bug ID: 2393800
Summary: CVE-2025-57833 python-django3: Django SQL injection in
FilteredRelation column aliases [epel-8]
Product: Fedora EPEL
Version: epel8
Status: NEW
Whiteboard: {"flaws": ["dfd08499-aebe-4510-b5c0-9c16c7266b91"]}
Component: python-django3
Keywords: Security, SecurityTracking
Severity: high
Priority: high
Assignee: michel(a)michel-slm.name
Reporter: abhraj(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
michel(a)michel-slm.name
Blocks: 2392990 (CVE-2025-57833)
Target Milestone: ---
Classification: Fedora
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability
management information. If something is wrong or missing, please contact a
member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essent…
Referenced Bugs:
https://bugzilla.redhat.com/show_bug.cgi?id=2392990
[Bug 2392990] CVE-2025-57833 django: Django SQL injection in FilteredRelation
column aliases
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2393800
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2365039
Bug ID: 2365039
Summary: CVE-2025-32873 python-django3: Django StripTags Denial
of Service [epel-8]
Product: Fedora EPEL
Version: epel8
Status: NEW
Whiteboard: {"flaws": ["97167560-5733-42ec-a135-f00f7dde8055"]}
Component: python-django3
Keywords: Security, SecurityTracking
Severity: medium
Priority: medium
Assignee: michel(a)michel-slm.name
Reporter: ahanwate(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
michel(a)michel-slm.name
Blocks: 2364980
Target Milestone: ---
Classification: Fedora
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2364980
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2365039
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2252960
Bug ID: 2252960
Summary: Handle correctly 'NO FOUND' in memached delete method
Product: Fedora EPEL
Version: epel8
Status: NEW
Component: python-django3
Assignee: michel(a)michel-slm.name
Reporter: zhechka.toteva(a)cern.ch
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
michel(a)michel-slm.name
Target Milestone: ---
Classification: Fedora
Created attachment 2002824
--> https://bugzilla.redhat.com/attachment.cgi?id=2002824&action=edit
patch that fixes the bug
Description of problem:
Version-Release number of selected component (if applicable):
python3-django3-3.2.20-1.el8.noarch
How reproducible:
With python-memcached 1.58.8 present in EPEL8 if a non-existing key
is attempted for deletion it raises an error
```
File "/usr/lib/python3.6/site-packages/memcache.py", line 584, in _deletetouch
% (cmd, ' or '.join(expected), line))
```
Actual results:
Expected results:
Additional info:
The fix is attached. The bug officially was fixed in 4.1, by commit
https://github.com/django/django/commit/05f3a6186efefc9fca2204a745b992501c6…
Cheers
Zhechka
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2252960
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2388310
Bug ID: 2388310
Summary: CVE-2025-55160 ImageMagick: ImageMagick: Undefined
Behavior [epel-8]
Product: Fedora EPEL
Version: epel8
Status: NEW
Whiteboard: {"flaws": ["0b3cfdbe-c45a-4777-9ada-cc90d7b34fae"]}
Component: ImageMagick
Keywords: Security, SecurityTracking
Severity: medium
Priority: medium
Assignee: luya_tfz(a)thefinalzone.net
Reporter: jmoroney(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: blaise(a)gmail.com, davide(a)cavalca.name,
epel-packagers-sig(a)lists.fedoraproject.org,
fedora(a)famillecollet.com, luya_tfz(a)thefinalzone.net,
michel(a)michel-slm.name, ngompa13(a)gmail.com,
pampelmuse(a)gmx.at
Blocks: 2388253
Target Milestone: ---
Classification: Fedora
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability
management information. If something is wrong or missing, please contact a
member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essent…
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2388310
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2379993
Bug ID: 2379993
Summary: CVE-2025-53101 ImageMagick: ImageMagick Stack Buffer
Overflow [epel-9]
Product: Fedora EPEL
Version: epel9
Status: NEW
Whiteboard: {"flaws": ["ba476b9c-f11d-4748-a286-60f4d582d0d3"]}
Component: ImageMagick
Keywords: Security, SecurityTracking
Severity: medium
Priority: medium
Assignee: luya_tfz(a)thefinalzone.net
Reporter: jmoroney(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: blaise(a)gmail.com, davide(a)cavalca.name,
epel-packagers-sig(a)lists.fedoraproject.org,
fedora(a)famillecollet.com, luya_tfz(a)thefinalzone.net,
michel(a)michel-slm.name, ngompa13(a)gmail.com,
pampelmuse(a)gmx.at
Blocks: 2379947
Target Milestone: ---
Classification: Fedora
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability
management information. If something is wrong or missing, please contact a
member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essent…
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2379993
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2379991
Bug ID: 2379991
Summary: CVE-2025-53019 ImageMagick: ImageMagick Memory Leak
[epel-9]
Product: Fedora EPEL
Version: epel9
Status: NEW
Whiteboard: {"flaws": ["e57171f0-4d11-4b12-a8fc-5c9c23647c32"]}
Component: ImageMagick
Keywords: Security, SecurityTracking
Severity: low
Priority: low
Assignee: luya_tfz(a)thefinalzone.net
Reporter: jmoroney(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: blaise(a)gmail.com, davide(a)cavalca.name,
epel-packagers-sig(a)lists.fedoraproject.org,
fedora(a)famillecollet.com, luya_tfz(a)thefinalzone.net,
michel(a)michel-slm.name, ngompa13(a)gmail.com,
pampelmuse(a)gmx.at
Blocks: 2379949
Target Milestone: ---
Classification: Fedora
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability
management information. If something is wrong or missing, please contact a
member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essent…
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2379991
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2379989
Bug ID: 2379989
Summary: CVE-2025-53101 ImageMagick: ImageMagick Stack Buffer
Overflow [epel-8]
Product: Fedora EPEL
Version: epel8
Status: NEW
Whiteboard: {"flaws": ["ba476b9c-f11d-4748-a286-60f4d582d0d3"]}
Component: ImageMagick
Keywords: Security, SecurityTracking
Severity: medium
Priority: medium
Assignee: luya_tfz(a)thefinalzone.net
Reporter: jmoroney(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: blaise(a)gmail.com, davide(a)cavalca.name,
epel-packagers-sig(a)lists.fedoraproject.org,
fedora(a)famillecollet.com, luya_tfz(a)thefinalzone.net,
michel(a)michel-slm.name, ngompa13(a)gmail.com,
pampelmuse(a)gmx.at
Blocks: 2379947
Target Milestone: ---
Classification: Fedora
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability
management information. If something is wrong or missing, please contact a
member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essent…
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2379989
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2379987
Bug ID: 2379987
Summary: CVE-2025-53015 ImageMagick: ImageMagick unbounded loop
[epel-9]
Product: Fedora EPEL
Version: epel9
Status: NEW
Whiteboard: {"flaws": ["c28019b4-019a-4b44-899d-8c1541627a9e"]}
Component: ImageMagick
Keywords: Security, SecurityTracking
Severity: medium
Priority: medium
Assignee: luya_tfz(a)thefinalzone.net
Reporter: jmoroney(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: blaise(a)gmail.com, davide(a)cavalca.name,
epel-packagers-sig(a)lists.fedoraproject.org,
fedora(a)famillecollet.com, luya_tfz(a)thefinalzone.net,
michel(a)michel-slm.name, ngompa13(a)gmail.com,
pampelmuse(a)gmx.at
Blocks: 2379948
Target Milestone: ---
Classification: Fedora
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability
management information. If something is wrong or missing, please contact a
member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essent…
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2379987
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2379986
Bug ID: 2379986
Summary: CVE-2025-53019 ImageMagick: ImageMagick Memory Leak
[epel-8]
Product: Fedora EPEL
Version: epel8
Status: NEW
Whiteboard: {"flaws": ["e57171f0-4d11-4b12-a8fc-5c9c23647c32"]}
Component: ImageMagick
Keywords: Security, SecurityTracking
Severity: low
Priority: low
Assignee: luya_tfz(a)thefinalzone.net
Reporter: jmoroney(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: blaise(a)gmail.com, davide(a)cavalca.name,
epel-packagers-sig(a)lists.fedoraproject.org,
fedora(a)famillecollet.com, luya_tfz(a)thefinalzone.net,
michel(a)michel-slm.name, ngompa13(a)gmail.com,
pampelmuse(a)gmx.at
Blocks: 2379949
Target Milestone: ---
Classification: Fedora
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability
management information. If something is wrong or missing, please contact a
member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essent…
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2379986
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…