fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the backend, which might allow local users to gain privileges via a crafted serialized object.
References
Configurations
History
No history.
Information
Published : 2011-07-21 23:55
Updated : 2025-04-11 00:51
NVD link : CVE-2011-2520
Mitre link : CVE-2011-2520
CVE.ORG link : CVE-2011-2520
JSON object : View
Products Affected
redhat
- system-config-firewall
fedoraproject
- fedora
CWE
CWE-502
Deserialization of Untrusted Data