Oval Definition:oval:org.mitre.oval:def:24851
Revision Date:2014-09-01Version:11
Title:ELSA-2014:0747: python-jinja2 security update (Moderate)
Description:Jinja2 is a template engine written in pure Python. It provides aDjango-inspired, non-XML syntax but supports inline expressions and anoptional sandboxed environment.It was discovered that Jinja2 did not properly handle bytecode cache filesstored in the system's temporary directory. A local attacker could use thisflaw to alter the output of an application using Jinja2 andFileSystemBytecodeCache, and potentially execute arbitrary code with theprivileges of that application. (CVE-2014-1402)All python-jinja2 users are advised to upgrade to these updated packages,which contain a backported patch to correct this issue. For the update totake effect, all applications using python-jinja2 must be restarted.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2014-1402
ELSA-2014:0747-00
Platform(s):Oracle Linux 6
Product(s):python-jinja2
Definition Synopsis
  • Oracle Linux 6.x
  • AND python-jinja2 is earlier than 0:2.2.1-2.el6_5
  • BACK