OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.
References
Link | Resource |
---|---|
http://lists.fedoraproject.org/pipermail/package-announce/2012-October/089472.html | Mailing List |
http://rhn.redhat.com/errata/RHSA-2012-1379.html | Third Party Advisory |
http://rhn.redhat.com/errata/RHSA-2013-0691.html | Not Applicable |
http://www.openwall.com/lists/oss-security/2012/09/05/16 | Mailing List |
http://www.openwall.com/lists/oss-security/2012/09/05/4 | Mailing List |
http://www.securityfocus.com/bid/55420 | Broken Link |
https://bugs.launchpad.net/swift/+bug/1006414 | Issue Tracking Patch |
https://bugzilla.redhat.com/show_bug.cgi?id=854757 | Issue Tracking Patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/79140 | Third Party Advisory VDB Entry |
https://github.com/openstack/swift/commit/e1ff51c04554d51616d2845f92ab726cb0e5831a | Patch |
https://launchpad.net/swift/+milestone/1.7.0 | Release Notes |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2012-10-22T23:00:00
Updated: 2017-08-28T12:57:01
Reserved: 2012-08-21T00:00:00
Link: CVE-2012-4406
JSON object: View
NVD Information
Status : Analyzed
Published: 2012-10-22T23:55:06.743
Modified: 2024-01-25T02:13:29.080
Link: CVE-2012-4406
JSON object: View
Redhat Information
No data.
CWE