-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 01 Feb 2018 18:10:22 +0000 Source: python-django Binary: python-django python-django-common python-django-doc python3-django Built-For-Profiles: nocheck Architecture: source all Version: 1:1.11.10-1~bpo9+1 Distribution: stretch-backports Urgency: medium Maintainer: Debian Python Modules Team <python-modules-team@lists.alioth.debian.org> Changed-By: Chris Lamb <la...@debian.org> Description: python-django - High-level Python web development framework (Python 2 version) python-django-common - High-level Python web development framework (common) python-django-doc - High-level Python web development framework (documentation) python3-django - High-level Python web development framework (Python 3 version) Changes: python-django (1:1.11.10-1~bpo9+1) stretch-backports; urgency=medium . * Rebuild for stretch-backports. . python-django (1:1.11.10-1) unstable; urgency=medium . * New upstream security release: - CVE-2018-6188: A regression in Django 1.11.8 made django.contrib.auth.forms.AuthenticationForm run its confirm_login_allowed() method even if an incorrect password is entered. This can leak information about a user, depending on what messages confirm_login_allowed() raises. If confirm_login_allowed() isn't overridden, an attacker enter an arbitrary username and see if that user has been set to is_active=False. If confirm_login_allowed() is overridden, more sensitive details could be leaked. * Use HTTPS "Format" URI in debian/copyright. . python-django (1:1.11.9-1) unstable; urgency=medium . * New upstream bugfix release. <https://docs.djangoproject.com/en/2.0/releases/1.11.9/> * Bump Standards-Version to 4.1.3. * Update debian/python-django-common.lintian-overrides for updated Lintian output. Checksums-Sha1: fd0057ecd590b683767b19a2f6ffe47bf63ad8d4 3187 python-django_1.11.10-1~bpo9+1.dsc 89bfa46eab1d594742d07e51fc0a9da569aedb24 24224 python-django_1.11.10-1~bpo9+1.debian.tar.xz fb2fac42196141470494406025048beeb10d5d79 1544618 python-django-common_1.11.10-1~bpo9+1_all.deb 5d0531491f888ff13a21f26610bb54fe49d636b0 2571442 python-django-doc_1.11.10-1~bpo9+1_all.deb 7325d2535bff4f182f06abcb9fc545968a74a5b0 916534 python-django_1.11.10-1~bpo9+1_all.deb 020b2a0d374c51fd952c792542a324d39ff5d50f 8299 python-django_1.11.10-1~bpo9+1_amd64.buildinfo b039c9385784f5def2de1369837a6b81cc2cb0f9 916260 python3-django_1.11.10-1~bpo9+1_all.deb Checksums-Sha256: 6e21a40241105a5899243f60fdcc020eee17f81c3fca997ddb2aef4844826615 3187 python-django_1.11.10-1~bpo9+1.dsc cc6ef1816d97c188ce401f5aad282df0c3bd72f8addea7b3b8a128e7ea229e5f 24224 python-django_1.11.10-1~bpo9+1.debian.tar.xz 7cf7d2186b836ba8215129a7b12bcd4fac396c2ef10490c3d37f565f2964f089 1544618 python-django-common_1.11.10-1~bpo9+1_all.deb 8c1fb0aff3d7488e2ad8a80760d419ff4ba95e26b91570640e4ebe555d5e3725 2571442 python-django-doc_1.11.10-1~bpo9+1_all.deb c47b43c2b7f5fb4ebda2ca5b798ea6d20d94575ffe02ff2043f9313f064ba245 916534 python-django_1.11.10-1~bpo9+1_all.deb 1aa52071bab5a1c01e9a6fcf34b0286ba2cab20aa31d2ad513dc3290621dc5b4 8299 python-django_1.11.10-1~bpo9+1_amd64.buildinfo 902a93d676d91c48513c65871f0102be59751fad4f3d9a59413fac45524d820e 916260 python3-django_1.11.10-1~bpo9+1_all.deb Files: 8d0dcfd619b014f15867e6f94a9e9080 3187 python optional python-django_1.11.10-1~bpo9+1.dsc ab0786f66a2df8efb415a320f68b2521 24224 python optional python-django_1.11.10-1~bpo9+1.debian.tar.xz 6864a7f4e37aae30c6b83e5e59174143 1544618 python optional python-django-common_1.11.10-1~bpo9+1_all.deb 6c2adf4f62d06730b4fa4b3abd26ef8b 2571442 doc optional python-django-doc_1.11.10-1~bpo9+1_all.deb ff3238cd62fd69228867bde48948a477 916534 python optional python-django_1.11.10-1~bpo9+1_all.deb b3560865218d9f0cddceae6d50fd9943 8299 python optional python-django_1.11.10-1~bpo9+1_amd64.buildinfo 4bb3806d9d98ebd73a21735b9b96dc93 916260 python optional python3-django_1.11.10-1~bpo9+1_all.deb
-----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAlpzWcQACgkQHpU+J9Qx HlhdiBAAr78Fu7zrA+uwtFB+6H4fUUWj65ampGGGanMBeZC6QPu+wOwD+m2QW8oP CsyLTvDHloEmk88X9EOTs82vg9sleMSozobgrdDlodOTxZbq8B0aXEZv1wL6hbQ2 7aph6fa0YLe5xGER2Hrx4X3yeY4oy6vljFanFmlFirtFsovZgSrh+Rd88Ge2jj2i +8VAxPEstFofTLFJCyywLECg+VoF6L30ItP8hCfxBClmP5zYNyPg0Dc7t1aajjZz Rlc8HVDDQwtuV+mja2SeP9Qc5qSW7wXujeL7AT47cEm6uUHDhrUGjkQpt/0zsTDf nDou0r+x+mlvtRUL5VjcKxMViocs0UDK+tsO/FwEYHok43P395Vja2pWwxLu4JYp Azi1gzbfKrsPooiViNrwdIC4XeZS2R7pXN/ij9cLMzwR+091UNn260xdDXIT4t5A PWdfA9zmuL/85vuuqTOigXslxgdZCOS1nwykJmVtAHKpq+RR8AHtjADzSZoRNk6G L7oQK4Y3NXPK1pN1cU8qW5VuLXTNZfxK7fUav2lhsO3eIFl1Eodz2w2ODEkl16y+ +I8sBIgMq3G1R4ZYlvWqtJz3Q2Lig+3uH7XrGhkUUp9ns6limiMPJXZBFr2IH1Up Tsk2U9iXW9FiGkPt08+MMOUxejQQwESHC8rrBHOcVGA+3a54l18= =oGa5 -----END PGP SIGNATURE----- _______________________________________________ Python-modules-team mailing list Python-modules-team@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/python-modules-team