CVE-2016-10745

NameCVE-2016-10745
DescriptionIn Pallets Jinja before 2.8.1, str.format allows a sandbox escape.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
jinja2 (PTS)stretch2.8-1vulnerable
buster2.10-2fixed
bullseye, sid2.11.2-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
jinja2source(unstable)2.9.4-1

Notes

[stretch] - jinja2 <no-dsa> (Minor issue)
[jessie] - jinja2 <no-dsa> (Minor issue)
Fixed by: https://github.com/pallets/jinja/commit/9b53045c34e61013dc8f09b7e52a555fa16bed16
Followup bugfix: https://github.com/pallets/jinja/commit/74bd64e56387f5b2931040dc7235a3509cde1611

Search for package or bug name: Reporting problems