New Debian jinja2 3.1.2-1+deb12u3 fixes: This update addresses the following issues: * jinja2: Jinja has a sandbox breakout through malicious filenames (CVE-2024-56201) * jinja2: Jinja has a sandbox breakout through indirect reference to format method (CVE-2024-56326) 3.1.2-1+deb12u3 (Sun, 18 May 2025 00:17:01 +0200) * CVE-2025-27516
--- mirror/ftp/pool/main/j/jinja2/jinja2_3.1.2-1+deb12u2.dsc +++ apt/ucs_5.2-0-errata5.2-3/source/jinja2_3.1.2-1+deb12u3.dsc @@ -1,3 +1,7 @@ +3.1.2-1+deb12u3 [Sun, 18 May 2025 00:17:01 +0200] Moritz Mühlenhoff <jmm@debian.org>: + + * CVE-2025-27516 (Closes: #1099690) + 3.1.2-1+deb12u2 [Thu, 27 Feb 2025 22:30:54 +0100] Lee Garrett <debian@rocketjump.eu>: * Non-maintainer upload by the LTS security team. <http://piuparts.knut.univention.de/5.2-3/#1792845769358902244>
OK: YAML OK: Tests OK: piuparts
<https://errata.software-univention.de/#/?erratum=5.2x194>