Back to search
CVE-2011-2520
Published: Jul 21, 2011
Modified: Aug 6, 2024
PUBLISHED
Description
fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the backend, which might allow local users to gain privileges via a crafted serialized object.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
FEDORA-2011-9652
vendor-advisory
x_refsource_FEDORA
systemconfigfirewall-priv-escalation(68734)
vdb-entry
x_refsource_XF
[oss-security] 20110718 CVE-2011-2520: flaw in system-config-firewall's usage of pickle allows privilege escalation
mailing-list
x_refsource_MLIST
https://bugzilla.redhat.com/show_bug.cgi?id=717985
x_refsource_CONFIRM
RHSA-2011:0953
vendor-advisory
x_refsource_REDHAT
48715
vdb-entry
x_refsource_BID
1025793
vdb-entry
x_refsource_SECTRACK
45294
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now