CyberRota Analysis
AI-GeneratedDjango versions 6.0 prior to 6.0.7 and 5.2 prior to 5.2.16 are vulnerable due to an over-read issue in the `GDALRaster` class, which can lead to the disclosure of adjacent memory or potential service degradation through segmentation faults. Organizations using these versions should prioritize patching to mitigate risks associated with data exposure and application stability. Additionally, users of earlier, unsupported Django series may also be at risk and should assess their environments accordingly.
Original NVD Description
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the `vsi_buffer` property is accessed. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)