PT-2011-1130 · Red Hat · System-Config-Printer-Udev+6

Published

2011-07-18

·

Updated

2024-01-21

·

CVE-2011-2520

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions system-config-firewall versions 1.2.29 and earlier system-config-firewall-base version 1.2.27 system-config-firewall-tui version 1.2.27 system-config-printer version 1.1.16 system-config-printer-libs version 1.1.16 system-config-printer-debuginfo version 1.1.16 system-config-printer-udev version 1.1.16
Description The issue affects the confidentiality, integrity, and availability of protected information in Red Hat Enterprise Linux. It can be exploited locally by an attacker who has passed the authentication procedure. The fw dbus.py in system-config-firewall uses the pickle Python module unsafely during D-Bus communication between the GUI and the backend, which might allow local users to gain privileges via a crafted serialized object.
Recommendations For system-config-firewall versions 1.2.29 and earlier, consider disabling the fw dbus.py script until a patch is available. For system-config-firewall-base version 1.2.27, restrict access to the vulnerable module to minimize the risk of exploitation. For system-config-firewall-tui version 1.2.27, avoid using the vulnerable component until the issue is resolved. For system-config-printer version 1.1.16, system-config-printer-libs version 1.1.16, system-config-printer-debuginfo version 1.1.16, and system-config-printer-udev version 1.1.16, restrict access to the vulnerable modules to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2015-06939
BDU:2015-06940
BDU:2015-06941
BDU:2015-06942
BDU:2015-06943
BDU:2015-06944
BDU:2015-06945
CVE-2011-2520
RHSA-2011:0953
RHSA-2011_0953

Affected Products

Red Hat
System-Config-Firewall
System-Config-Firewall-Base
System-Config-Printer
System-Config-Printer-Debuginfo
System-Config-Printer-Libs
System-Config-Printer-Udev