CVE-2011-2520

fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the backend, which might allow local users to gain privileges via a crafted serialized object.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 27%
Affected Products (NVD)
VendorProductVersion
redhatsystem-config-firewall
𝑥
≤ 1.2.29
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
system-config-printer
hardy
ignored
lucid
not-affected
maverick
not-affected
natty
not-affected
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
system-config-firewall
RHEL 6
0:1.2.27-3.el6_1.3
fixed
system-config-firewall-base
RHEL 6
0:1.2.27-3.el6_1.3
fixed
system-config-firewall-tui
RHEL 6
0:1.2.27-3.el6_1.3
fixed
system-config-printer
RHEL 6
0:1.1.16-17.el6_1.2
fixed
system-config-printer-libs
RHEL 6
0:1.1.16-17.el6_1.2
fixed
system-config-printer-udev
RHEL 6
0:1.1.16-17.el6_1.2
fixed