LWN.net Logo

python-django-piston: remote code execution

Package(s):python-django-piston CVE #(s):CVE-2011-4103
Created:November 14, 2011 Updated:November 16, 2011
Description: From the Debian advisory:

It was discovered that the Piston framework can deserialize untrusted YAML and Pickle data, leading to remote code execution.

Alerts:
Debian DSA-2344-1 2011-11-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds