Description
The get_image_dimensions function in the image-handling functionality in Django before 1.3.2 and 1.4.x before 1.4.1 uses a constant chunk size in all attempts to determine dimensions, which allows remote attackers to cause a denial of service (process or thread consumption) via a large TIFF image.
Remediation
References
Related Vulnerabilities
Liferay Portal Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2022-42129)
WordPress Plugin Tutor LMS-eLearning and online course solution Security Bypass (2.7.0)
WordPress Plugin InfiniteWP Client Security Bypass (1.3.7)
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2016-6635)