CVE-2014-0474: Canonical Ubuntu Linux
High severity, CVSS 10.0. EPSS: 4.9% chance of exploitation in the next 30 days.
The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."
Affected products
- Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 12.10 only; version 13.10 only; version 14.04 only
- Djangoproject Django: version 1.6 only; version 1.6.1 only; version 1.6.2 only; up to and including 1.4.10; version 1.4 only; version 1.4.1 only; …
Published 2014-04-23. Last modified 2026-06-17.