|
|
Log in / Subscribe / Register

system-config-firewall: privilege escalation/arbitrary code execution

Package(s):system-config-firewall CVE #(s):CVE-2011-2520
Created:July 19, 2011 Updated:August 2, 2011
Description: From the Red Hat advisory:

It was found that system-config-firewall used the Python pickle module in an insecure way when sending data (via D-Bus) to the privileged back-end mechanism. A local user authorized to configure firewall rules using system-config-firewall could use this flaw to execute arbitrary code with root privileges, by sending a specially-crafted serialized object.

Alerts:
Fedora FEDORA-2011-9652 system-config-firewall 2011-07-23
Scientific Linux SL-syst-20110718 system-config-firewall 2011-07-18
Red Hat RHSA-2011:0953-01 system-config-firewall 2011-07-18

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds