Critical Django security updates released (0day, exploit in the wild)
djangoproject.com
djangoproject.com
If you've got Java applet support in your browser, here's an animated example...
http://regex.powertoy.org/?pat=m/((a{0,5}){0,5})*[e]/g&a...
...based on the "WARNING: Particularly complicated..." example in the Perlre docs:
http://perldoc.perl.org/perlre.html
You can see that Django's problematic domain-validation regexes were similar to the perlre example, but even worse -- a one-or-more of unbounded length, inside a 0-or-more of unbounded length, inside a 1-or-more of unbounded length:
http://www.checkmarx.com/Upload/Documents/PDF/Checkmarx_OWAS... [pdf]
Quick view: https://docs.google.com/gview?url=http%3A%2F%2Fwww.checkmarx...
P. S. Corrected wording.
When debating whether a particular issue impacts security, we ask that you err on the side of caution and always contact security@djangoproject.com; we will be more than happy to work with you in analyzing and assessing potential security issues.
That way, the people that missed the issue in the first place are the only ones that will have the opportunity to fix it. While you wait, the crackers have already compromised your site.
In this case, it was a mistake. Luckily, it's only a DOS - there's worse things that could happen.
Everybody else will probably squeak by without harm.