Oval Definition:oval:com.redhat.rhsa:def:20140747
Revision Date:2014-06-11Version:636
Title:RHSA-2014:0747: python-jinja2 security update (Moderate)
Description:Jinja2 is a template engine written in pure Python. It provides a Django-inspired, non-XML syntax but supports inline expressions and an optional sandboxed environment.

  • It was discovered that Jinja2 did not properly handle bytecode cache files stored in the system's temporary directory. A local attacker could use this flaw to alter the output of an application using Jinja2 and FileSystemBytecodeCache, and potentially execute arbitrary code with the privileges of that application. (CVE-2014-1402)

    All python-jinja2 users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. For the update to take effect, all applications using python-jinja2 must be restarted.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2014-1402
    CVE-2014-1402
    RHSA-2014:0747
    RHSA-2014:0747-00
    RHSA-2014:0747-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND python-jinja2 is earlier than 0:2.2.1-2.el6_5
  • AND python-jinja2 is signed with Red Hat redhatrelease2 key
  • BACK