CVE Vulnerabilities

CVE-2014-1402

Published: May 19, 2014 | Modified: Dec 22, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
4.4 MODERATE
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with _jinja2 in /tmp.

Affected Software

Name Vendor Start Version End Version
Jinja2 Pocoo * 2.7.1 (including)
Jinja2 Pocoo 2.0 (including) 2.0 (including)
Jinja2 Pocoo 2.0-rc1 (including) 2.0-rc1 (including)
Jinja2 Pocoo 2.1 (including) 2.1 (including)
Jinja2 Pocoo 2.1.1 (including) 2.1.1 (including)
Jinja2 Pocoo 2.2 (including) 2.2 (including)
Jinja2 Pocoo 2.2.1 (including) 2.2.1 (including)
Jinja2 Pocoo 2.3 (including) 2.3 (including)
Jinja2 Pocoo 2.3.1 (including) 2.3.1 (including)
Jinja2 Pocoo 2.4 (including) 2.4 (including)
Jinja2 Pocoo 2.4.1 (including) 2.4.1 (including)
Jinja2 Pocoo 2.5 (including) 2.5 (including)
Jinja2 Pocoo 2.5.1 (including) 2.5.1 (including)
Jinja2 Pocoo 2.5.2 (including) 2.5.2 (including)
Jinja2 Pocoo 2.5.3 (including) 2.5.3 (including)
Jinja2 Pocoo 2.5.4 (including) 2.5.4 (including)
Jinja2 Pocoo 2.5.5 (including) 2.5.5 (including)
Jinja2 Pocoo 2.6 (including) 2.6 (including)
Jinja2 Pocoo 2.7 (including) 2.7 (including)
Red Hat Enterprise Linux 6 RedHat python-jinja2-0:2.2.1-2.el6_5 *
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 RedHat python27-python-jinja2-0:2.6-10.el6 *
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 RedHat python33-python-jinja2-0:2.6-11.el6 *
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.3 EUS RedHat python27-python-jinja2-0:2.6-10.el6 *
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.3 EUS RedHat python33-python-jinja2-0:2.6-11.el6 *
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUS RedHat python27-python-jinja2-0:2.6-10.el6 *
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUS RedHat python33-python-jinja2-0:2.6-11.el6 *
Red Hat Software Collections 1 for Red Hat Enterprise Linux 7 RedHat python27-python-jinja2-0:2.6-11.el7 *
Red Hat Software Collections 1 for Red Hat Enterprise Linux 7 RedHat python33-python-jinja2-0:2.6-12.el7 *
Jinja2 Ubuntu lucid *
Jinja2 Ubuntu precise *
Jinja2 Ubuntu quantal *
Jinja2 Ubuntu raring *
Jinja2 Ubuntu saucy *
Jinja2 Ubuntu upstream *

References