Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.881951
Kategorie:CentOS Local Security Checks
Titel:CentOS Update for python-jinja2 CESA-2014:0747 centos6
Zusammenfassung:The remote host is missing an update for the 'python-jinja2'; package(s) announced via the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'python-jinja2'
package(s) announced via the referenced advisory.

Vulnerability Insight:
Jinja2 is a template engine written in pure Python. It
provides a Django-inspired, non-XML syntax but supports inline expressions and
an optional sandboxed environment.

It was discovered that Jinja2 did not properly handle bytecode cache files
stored in the system's temporary directory. A local attacker could use this
flaw to alter the output of an application using Jinja2 and
FileSystemBytecodeCache, and potentially execute arbitrary code with the
privileges of that application. (CVE-2014-1402)

All python-jinja2 users are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. For the update to
take effect, all applications using python-jinja2 must be restarted.

Affected Software/OS:
python-jinja2 on CentOS 6

Solution:
Please install the updated packages.

CVSS Score:
4.4

CVSS Vector:
AV:L/AC:M/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2014-1402
http://www.gentoo.org/security/en/glsa/glsa-201408-13.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2014:096
https://oss.oracle.com/pipermail/el-errata/2014-June/004192.html
http://openwall.com/lists/oss-security/2014/01/10/2
http://openwall.com/lists/oss-security/2014/01/10/3
RedHat Security Advisories: RHSA-2014:0747
http://rhn.redhat.com/errata/RHSA-2014-0747.html
RedHat Security Advisories: RHSA-2014:0748
http://rhn.redhat.com/errata/RHSA-2014-0748.html
http://secunia.com/advisories/56287
http://secunia.com/advisories/58783
http://secunia.com/advisories/58918
http://secunia.com/advisories/59017
http://secunia.com/advisories/60738
http://secunia.com/advisories/60770
CopyrightCopyright (C) 2014 Greenbone AG

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.