CVE-2007-5712
Last modified
CVE-2007-5712 is a vulnerability of currently unknown severity. The internationalization (i18n) framework in Django 0.91, 0.95, 0.95.1, and 0.96, and as used in other products such as PyLucid, when the USE_I18N option and the i18n component are enabled, allows remote attackers to cause a denial of service (memory consumption) via many HTTP requests with large Accept-Language headers.. EPSS estimates a 1.80% chance of exploitation in the next 30 days.
Description
The internationalization (i18n) framework in Django 0.91, 0.95, 0.95.1, and 0.96, and as used in other products such as PyLucid, when the USE_I18N option and the i18n component are enabled, allows remote attackers to cause a denial of service (memory consumption) via many HTTP requests with large Accept-Language headers.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Django Project | Django | 0.91 |
| Django Project | Django | 0.95 |
| Django Project | Django | 0.95.1 |
| Django Project | Django | 0.96 |
References
- http://secunia.com/advisories/27435Patch, Vendor Advisory
- http://secunia.com/advisories/27597Vendor Advisory
- http://secunia.com/advisories/31961Vendor Advisory
- http://www.vupen.com/english/advisories/2007/3660Vendor Advisory
- http://www.vupen.com/english/advisories/2007/3661Vendor Advisory
- http://secunia.com/advisories/27435Patch, Vendor Advisory
- http://secunia.com/advisories/27597Vendor Advisory
- http://secunia.com/advisories/31961Vendor Advisory
- http://www.vupen.com/english/advisories/2007/3660Vendor Advisory
- http://www.vupen.com/english/advisories/2007/3661Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-5712?
How severe is CVE-2007-5712?
How do I fix CVE-2007-5712?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-5706Absolute path traversal vulnerability in download.php in Jee…
- CVE-2007-5707OpenLDAP before 2.3.39 allows remote attackers to cause a de…
- CVE-2007-5708slapo-pcache (overlays/pcache.c) in slapd in OpenLDAP before…
- CVE-2007-5709Stack-based buffer overflow in Sony SonicStage CONNECT Playe…
- CVE-2007-5710Cross-site scripting (XSS) vulnerability in wp-admin/edit-po…
- CVE-2007-5711Massive Entertainment World in Conflict 1.001 and earlier al…
- CVE-2007-5713Off-by-one error in the GeoIP module in the AMX Mod X 1.76d …
- CVE-2007-5714The Gentoo ebuild of MLDonkey before 2.9.0-r3 has a p2p user…
- CVE-2007-5715DenyHosts 2.6 processes OpenSSH sshd "not listed in AllowUse…
- CVE-2007-5716Unspecified vulnerability in the Internet Protocol (IP) func…
- CVE-2007-5717Unspecified vulnerability in Sun Fire X2100 M2 and X2200 M2 …
- CVE-2007-5718vobcopy 0.5.14 allows local users to append data to an arbit…
Are you affected by CVE-2007-5712?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
