Описание
The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with _jinja2 in /tmp.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 7 | python-jinja2 | Not affected | ||
| Red Hat OpenStack Platform 4 | python-jinja2-26 | Affected | ||
| Red Hat Enterprise Linux 6 | python-jinja2 | Fixed | RHSA-2014:0747 | 11.06.2014 |
| Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 | python27-python-jinja2 | Fixed | RHSA-2014:0748 | 11.06.2014 |
| Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 | python33-python-jinja2 | Fixed | RHSA-2014:0748 | 11.06.2014 |
| Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.3 EUS | python27-python-jinja2 | Fixed | RHSA-2014:0748 | 11.06.2014 |
| Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.3 EUS | python33-python-jinja2 | Fixed | RHSA-2014:0748 | 11.06.2014 |
| Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUS | python27-python-jinja2 | Fixed | RHSA-2014:0748 | 11.06.2014 |
| Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUS | python33-python-jinja2 | Fixed | RHSA-2014:0748 | 11.06.2014 |
| Red Hat Software Collections 1 for Red Hat Enterprise Linux 7 | python27-python-jinja2 | Fixed | RHSA-2014:0748 | 11.06.2014 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.4 Medium
CVSS2
Связанные уязвимости
The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with __jinja2_ in /tmp.
The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with __jinja2_ in /tmp.
The default configuration for bccache.FileSystemBytecodeCache in Jinja ...
ELSA-2014-0747: python-jinja2 security update (MODERATE)
EPSS
4.4 Medium
CVSS2