{"id":"MGASA-2014-0028","summary":"Updated python-jinja2 package fixes two security vulnerabilities","details":"Updated python-jinja2 packages fix security vulnerability:\n\nJinja2, a template engine written in pure python, was found to use /tmp \nas a default directory for jinja2.bccache.FileSystemBytecodeCache, which \nis insecure because the /tmp directory is world-writable and the \nfilenames used like 'FileSystemBytecodeCache' are often predictable. A \nmalicious user could exploit this bug to execute arbitrary code as \nanother user. (CVE-2014-1402)\n","modified":"2026-04-16T06:23:24.610391562Z","published":"2014-01-24T21:04:09Z","upstream":["CVE-2014-1402"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0028.html"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2014/01/10/2"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2014/01/10/3"},{"type":"REPORT","url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=734747"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1051421"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=12265"}],"affected":[{"package":{"name":"python-jinja2","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/python-jinja2?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.5-8.2.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0028.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}