CVE-2014-1402
Publication date 19 May 2014
Last updated 24 July 2024
Ubuntu priority
The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with __jinja2_ in /tmp.
Status
Package | Ubuntu Release | Status |
---|---|---|
jinja2 | 14.04 LTS trusty |
Not affected
|
Notes
mdeslaur
upstream commit below included in 2.7.2 introduces a temp file issue, which is CVE-2014-0012
References
Related Ubuntu Security Notices (USN)
- USN-2301-1
- Jinja2 vulnerabilities
- 24 July 2014