CVE-2011-2520
Publication date 21 July 2011
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the backend, which might allow local users to gain privileges via a crafted serialized object.
Status
Package | Ubuntu Release | Status |
---|---|---|
system-config-printer | ||
Notes
mdeslaur
This is actually a flaw in the system-config-firewall backend. system-config-printer opens pickles from the backend, but since we don't ship the backend (system-config-firewall), we're not affected.
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.8 · High |
Attack vector | Local |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |