ALT-PU-2024-8948-5
Package python3-module-babel updated to version 2.14.0-alt1.1 for branch p10 in task 350773.
Closed vulnerabilities
Published: 2021-10-21
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2021-42771
Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution.
Severity: HIGH (7.8)
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References:
- https://github.com/python-babel/babel/pull/782
- https://github.com/python-babel/babel/pull/782
- https://lists.debian.org/debian-lts/2021/10/msg00040.html
- https://lists.debian.org/debian-lts/2021/10/msg00040.html
- [debian-lts-announce] 20211021 [SECURITY] [DLA 2790-1] python-babel security update
- [debian-lts-announce] 20211021 [SECURITY] [DLA 2790-1] python-babel security update
- DSA-5018
- DSA-5018
- https://www.tenable.com/security/research/tra-2021-14
- https://www.tenable.com/security/research/tra-2021-14