fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the backend, which might allow local users to gain privileges via a crafted serialized object.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2011-07-21 23:55
Updated : 2017-08-29 01:29
NVD link : CVE-2011-2520
Mitre link : CVE-2011-2520
JSON object : View
Products Affected
redhat
- system-config-firewall
CWE
CWE-264
Permissions, Privileges, and Access Controls
