CVE-2011-2520
Publication date 21 July 2011
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the backend, which might allow local users to gain privileges via a crafted serialized object.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| system-config-printer | ||
Notes
mdeslaur
This is actually a flaw in the system-config-firewall backend. system-config-printer opens pickles from the backend, but since we don't ship the backend (system-config-firewall), we're not affected.
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score |
|
| Attack vector | Local |
| Attack complexity | Low |
| Privileges required | Low |
| User interaction | None |
| Scope | Unchanged |
| Confidentiality | High |
| Integrity impact | High |
| Availability impact | High |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |