CVE-2014-0012
Publication date 19 May 2014
Last updated 24 July 2024
Ubuntu priority
FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.
Status
Package | Ubuntu Release | Status |
---|---|---|
jinja2 | 14.04 LTS trusty |
Not affected
|
Notes
mdeslaur
Introduced in 2.7.2, and in CVE-2014-1402 security fix. 2.7.2-2 in trusty switches to tempfile.mkdtemp which fixes the security issue, but isn't an ideal fix for proper caching.
References
Related Ubuntu Security Notices (USN)
- USN-2301-1
- Jinja2 vulnerabilities
- 24 July 2014