Lucene search

K
amazonAmazonALAS-2014-371
HistoryJul 09, 2014 - 4:39 p.m.

Medium: python-jinja2

2014-07-0916:39:00
alas.aws.amazon.com
12

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

10.1%

Issue Overview:

The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with _jinja2 in /tmp.

Affected Packages:

python-jinja2

Issue Correction:
Run yum update python-jinja2 to update your system.

New Packages:

noarch:  
    python-jinja2-2.7.2-2.10.amzn1.noarch  
  
src:  
    python-jinja2-2.7.2-2.10.amzn1.src  

Additional References

Red Hat: CVE-2014-1402

Mitre: CVE-2014-1402

OSVersionArchitecturePackageVersionFilename
Amazon Linux1noarchpython-jinja2< 2.7.2-2.10.amzn1python-jinja2-2.7.2-2.10.amzn1.noarch.rpm

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

10.1%