LWN.net Logo

openstack-swift: insecure use of python pickle

Package(s):openstack-swift CVE #(s):CVE-2012-4406
Created:October 8, 2012 Updated:October 18, 2012
Description: From the Red Hat bugzilla:

Sebastian Krahmer (krahmer@suse.de) reports:

swift uses pickle to store and load meta data. pickle is insecure and allows to execute arbitrary code in loads().

Alerts:
Fedora FEDORA-2012-15098 2012-10-08
Red Hat RHSA-2012:1379-01 2012-10-16
Fedora FEDORA-2012-15642 2012-10-18

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds