CVE-2014-0481: Debian Linux
Medium severity, CVSS 4.3. EPSS: 2.5% chance of exploitation in the next 30 days.
The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploaded, which allows remote attackers to cause a denial of service (CPU consumption) by unloading a multiple files with the same name.
Affected products
- Debian Debian Linux: version 7.0 only
- Djangoproject Django: up to and including 1.4.13; version 1.4 only; version 1.4.1 only; version 1.4.2 only; version 1.4.4 only; version 1.4.5 only; …
- Opensuse Opensuse: version 13.1 only
- Opensuse Project Opensuse: version 12.3 only
Published 2014-08-26. Last modified 2026-06-17.