diff --git a/docs/howto/custom-file-storage.txt b/docs/howto/custom-file-storage.txt index afa1c9a908..56aa479a22 100644 --- a/docs/howto/custom-file-storage.txt +++ b/docs/howto/custom-file-storage.txt @@ -97,7 +97,7 @@ to the ``get_valid_name()`` method described above. extension. Previously, an underscore followed by a number (e.g. ``"_1"``, ``"_2"``, - etc.) was appended to the filename until an avaible name in the destination + etc.) was appended to the filename until an available name in the destination directory was found. A malicious user could exploit this deterministic algorithm to create a denial-of-service attack. This change was also made in Django 1.6.6, 1.5.9, and 1.4.14. diff --git a/docs/ref/files/storage.txt b/docs/ref/files/storage.txt index 3200ec3914..f2578e7f63 100644 --- a/docs/ref/files/storage.txt +++ b/docs/ref/files/storage.txt @@ -119,7 +119,7 @@ The Storage Class extension. Previously, an underscore followed by a number (e.g. ``"_1"``, ``"_2"``, - etc.) was appended to the filename until an avaible name in the + etc.) was appended to the filename until an available name in the destination directory was found. A malicious user could exploit this deterministic algorithm to create a denial-of-service attack. This change was also made in Django 1.6.6, 1.5.9, and 1.4.14.