VDB
CVE-2011-2520
CVE-2011-2520
PUBLISHED
CVSS 7.800000190734863 HIGH
fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the backend, which might allow local users to gain privileges via a crafted serialized object.
EPSS 0.42% · 35.0th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.42%
35.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| redhat | system-config-firewall | 0 |
| fedoraproject | fedora | 15 |
Timeline
- Jul 19, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
References
- systemconfigfirewall-priv-escalation(68734) vdb
- [oss-security] 20110718 CVE-2011-2520: flaw in system-config-firewall's usage of pickle allows privilege escalation mailing-list
- https://bugzilla.redhat.com/show_bug.cgi?id=717985 url
- 1025793 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2011-2520 advisory
- https://access.redhat.com/errata/RHSA-2011:0953 url
- https://access.redhat.com/security/cve/CVE-2011-2520 url
- http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063314.html mailing_list
- http://secunia.com/advisories/45294 technical
- http://www.redhat.com/support/errata/RHSA-2011-0953.html technical
- http://www.securityfocus.com/bid/48715 technical