ALT-PU-2021-2513-1
Package python3-module-babel updated to version 2.9.1-alt1 for branch sisyphus in task 282703.
Closed vulnerabilities
                                                                                    Published: 2021-10-20
Modified: 2024-11-21
                                                                            Modified: 2024-11-21
CVE-2021-42771
Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution.
                                                                                        
                                                                                        
                                                                                            Severity: HIGH (7.2)
                                                                                        
                                                                                        
                                                                                        
                                                                                        
                                                                                            Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
                                                                                        
                                                                                        
                                                                                    
                                                                                
                                                                                        
                                                                                        
                                                                                            Severity: HIGH (7.8)
                                                                                        
                                                                                        
                                                                                        
                                                                                        
                                                                                            Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
                                                                                        
                                                                                        
                                                                                    
                                                                                References:
                                                                        - https://github.com/python-babel/babel/pull/782
 - https://lists.debian.org/debian-lts-announce/2021/10/msg00018.html
 - https://lists.debian.org/debian-lts/2021/10/msg00040.html
 - https://www.debian.org/security/2021/dsa-5018
 - https://www.tenable.com/security/research/tra-2021-14
 - https://github.com/python-babel/babel/pull/782
 - https://lists.debian.org/debian-lts-announce/2021/10/msg00018.html
 - https://lists.debian.org/debian-lts/2021/10/msg00040.html
 - https://www.debian.org/security/2021/dsa-5018
 - https://www.tenable.com/security/research/tra-2021-14