{"id":31476,"date":"2019-06-06T20:14:04","date_gmt":"2019-06-06T11:14:04","guid":{"rendered":"https:\/\/jirak.net\/wp\/usn-4011-1-jinja2-vulnerabilities\/"},"modified":"2019-06-06T22:34:20","modified_gmt":"2019-06-06T13:34:20","slug":"usn-4011-1-jinja2-vulnerabilities","status":"publish","type":"post","link":"https:\/\/jirak.net\/wp\/usn-4011-1-jinja2-vulnerabilities\/","title":{"rendered":"USN-4011-1: Jinja2 vulnerabilities"},"content":{"rendered":"<p>USN-4011-1: Jinja2 vulnerabilities<\/p>\n<h2 id=\"jinja2-vulnerabilities\">jinja2 vulnerabilities<\/h2>\n<p>A security issue affects these releases of Ubuntu and its derivatives:<\/p>\n<ul>\n<li>Ubuntu 19.04<\/li>\n<li>Ubuntu 18.10<\/li>\n<li>Ubuntu 18.04 LTS<\/li>\n<li>Ubuntu 16.04 LTS<\/li>\n<\/ul>\n<h3 id=\"summary\">Summary<\/h3>\n<p>Several security issues were fixed in Jinja2.<\/p>\n<h3 id=\"software-description\">Software Description<\/h3>\n<ul>\n<li>jinja2 &#8211; small but fast and easy to use stand-alone template engine<\/li>\n<\/ul>\n<h3 id=\"details\">Details<\/h3>\n<p>Olivier Dony discovered that Jinja incorrectly handled str.format. An<br \/>\nattacker could possibly use this issue to escape the sandbox. This issue<br \/>\nonly affected Ubuntu 16.04 LTS. (CVE-2016-10745)<\/p>\n<p>Brian Welch discovered that Jinja incorrectly handled str.format_map. An<br \/>\nattacker could possibly use this issue to escape the sandbox.<br \/>\n(CVE-2019-10906)<\/p>\n<h2 id=\"update-instructions\">Update instructions<\/h2>\n<p>The problem can be corrected by updating your system to the following package versions:<\/p>\n<dl>\n<dt>Ubuntu 19.04<\/dt>\n<dd><a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/jinja2\">python-jinja2<\/a> &#8211; <a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/jinja2\/2.10-1ubuntu0.19.04.1\">2.10-1ubuntu0.19.04.1<\/a><\/dd>\n<dd><a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/jinja2\">python3-jinja2<\/a> &#8211; <a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/jinja2\/2.10-1ubuntu0.19.04.1\">2.10-1ubuntu0.19.04.1<\/a><\/dd>\n<dt>Ubuntu 18.10<\/dt>\n<dd><a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/jinja2\">python-jinja2<\/a> &#8211; <a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/jinja2\/2.10-1ubuntu0.18.10.1\">2.10-1ubuntu0.18.10.1<\/a><\/dd>\n<dd><a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/jinja2\">python3-jinja2<\/a> &#8211; <a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/jinja2\/2.10-1ubuntu0.18.10.1\">2.10-1ubuntu0.18.10.1<\/a><\/dd>\n<dt>Ubuntu 18.04 LTS<\/dt>\n<dd><a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/jinja2\">python-jinja2<\/a> &#8211; <a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/jinja2\/2.10-1ubuntu0.18.04.1\">2.10-1ubuntu0.18.04.1<\/a><\/dd>\n<dd><a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/jinja2\">python3-jinja2<\/a> &#8211; <a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/jinja2\/2.10-1ubuntu0.18.04.1\">2.10-1ubuntu0.18.04.1<\/a><\/dd>\n<dt>Ubuntu 16.04 LTS<\/dt>\n<dd><a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/jinja2\">python-jinja2<\/a> &#8211; <a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/jinja2\/2.8-1ubuntu0.1\">2.8-1ubuntu0.1<\/a><\/dd>\n<dd><a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/jinja2\">python3-jinja2<\/a> &#8211; <a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/jinja2\/2.8-1ubuntu0.1\">2.8-1ubuntu0.1<\/a><\/dd>\n<\/dl>\n<p>To update your system, please follow these instructions: <a href=\"https:\/\/wiki.ubuntu.com\/Security\/Upgrades\">https:\/\/wiki.ubuntu.com\/Security\/Upgrades<\/a>.<\/p>\n<p>In general, a standard system update will make all the necessary changes.<\/p>\n<h2 id=\"references\">References<\/h2>\n<ul>\n<li><a href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/CVE-2016-10745\">CVE-2016-10745<\/a><\/li>\n<li><a href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/CVE-2019-10906\">CVE-2019-10906<\/a><\/li>\n<\/ul>\n<p>Source: <a href=\"https:\/\/usn.ubuntu.com\/4011-1\/\" target=\"_blank\" rel=\"noopener noreferrer\">USN-4011-1: Jinja2 vulnerabilities<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<div class=\"mh-excerpt\"><p>USN-4011-1: Jinja2 vulnerabilities jinja2 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in Jinja2. Software Description jinja2 &#8211; small but fast and easy to use stand-alone template engine Details Olivier Dony discovered that Jinja incorrectly handled str.format. An attacker could possibly use this issue to escape the sandbox. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10745) Brian Welch discovered that Jinja incorrectly handled str.format_map. An attacker could possibly use this issue to escape the sandbox. (CVE-2019-10906) Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 python-jinja2 &#8211; 2.10-1ubuntu0.19.04.1 python3-jinja2 &#8211; 2.10-1ubuntu0.19.04.1 Ubuntu 18.10 python-jinja2 &#8211; 2.10-1ubuntu0.18.10.1 python3-jinja2 &#8211; 2.10-1ubuntu0.18.10.1 Ubuntu 18.04 LTS python-jinja2 &#8211; 2.10-1ubuntu0.18.04.1 python3-jinja2 &#8211; 2.10-1ubuntu0.18.04.1 Ubuntu 16.04 LTS <a class=\"mh-excerpt-more\" href=\"https:\/\/jirak.net\/wp\/usn-4011-1-jinja2-vulnerabilities\/\" title=\"USN-4011-1: Jinja2 vulnerabilities\">[ more&#8230; ]<\/a><\/p>\n<\/div>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[586],"tags":[587],"class_list":["post-31476","post","type-post","status-publish","format-standard","hentry","category-ubuntu-usn","tag-ubuntu-usn"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts\/31476","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/comments?post=31476"}],"version-history":[{"count":1,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts\/31476\/revisions"}],"predecessor-version":[{"id":31477,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts\/31476\/revisions\/31477"}],"wp:attachment":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/media?parent=31476"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/categories?post=31476"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/tags?post=31476"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}