CVE-2011-2520

fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the backend, which might allow local users to gain privileges via a crafted serialized object.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:system-config-firewall:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:fedoraproject:fedora:15:*:*:*:*:*:*:*

History

No history.

Information

Published : 2011-07-21 23:55

Updated : 2024-01-21 02:53


NVD link : CVE-2011-2520

Mitre link : CVE-2011-2520

CVE.ORG link : CVE-2011-2520


JSON object : View

Products Affected

fedoraproject

  • fedora

redhat

  • system-config-firewall
CWE
CWE-502

Deserialization of Untrusted Data