summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorTim Graham <timograham@gmail.com>2019-02-11 16:08:50 -0500
committerTim Graham <timograham@gmail.com>2019-02-11 16:15:08 -0500
commit8ded2c5fbbf2cc7ea7eef5c5a37b2f6339f06e31 (patch)
tree29b1ef18eaf52e0db4a8796023d934baa5e18ff2
parent392e040647403fc8007708d52ce01d915b014849 (diff)
downloaddjango-8ded2c5fbbf2cc7ea7eef5c5a37b2f6339f06e31.tar.gz
[2.0.x] Added CVE-2019-6975 to the security release archive.
Backport of d6e5aad5c7eba3d8061c09902de16cd2b22619af from master.
-rw-r--r--docs/releases/security.txt14
1 files changed, 14 insertions, 0 deletions
diff --git a/docs/releases/security.txt b/docs/releases/security.txt
index d62ebd96df..cce666ce99 100644
--- a/docs/releases/security.txt
+++ b/docs/releases/security.txt
@@ -922,3 +922,17 @@ Versions affected
* Django 2.1 :commit:`(patch) <64d2396e83aedba3fcc84ca40f23fbd22f0b9b5b>`
* Django 2.0 :commit:`(patch) <9f4ed7c94c62e21644ef5115e393ac426b886f2e>`
* Django 1.11 :commit:`(patch) <1cd00fcf52d089ef0fe03beabd05d59df8ea052a>`
+
+February 11, 2019 - :cve:`2019-6975`
+------------------------------------
+
+Memory exhaustion in ``django.utils.numberformat.format()``. `Full description
+<https://www.djangoproject.com/weblog/2019/feb/11/security-releases/>`__
+
+Versions affected
+~~~~~~~~~~~~~~~~~
+
+* Django 2.1 :commit:`(patch) <40cd19055773705301c3428ed5e08a036d2091f3>`
+* Django 2.0 :commit:`(patch <1f42f82566c9d2d73aff1c42790d6b1b243f7676>` and
+ :commit:`correction) <392e040647403fc8007708d52ce01d915b014849>`
+* Django 1.11 :commit:`(patch) <0bbb560183fabf0533289700845dafa94951f227>`