CRITICAL 9.8 PyPI
OpenStack Object Storage (swift) Code Injection vulnerability
GHSA-v7mh-3jgf-r26c · CVE-2012-4406 · PYSEC-2026-545
Published · Modified
Description
OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2012-4406
- WEB https://github.com/openstack/swift/commit/e1ff51c04554d51616d2845f92ab726cb0e5831a
- WEB https://access.redhat.com/errata/RHSA-2012:1379
- WEB https://access.redhat.com/errata/RHSA-2013:0691
- WEB https://access.redhat.com/security/cve/CVE-2012-4406
- WEB https://bugs.launchpad.net/swift/+bug/1006414
- WEB https://bugzilla.redhat.com/show_bug.cgi?id=854757
- WEB https://exchange.xforce.ibmcloud.com/vulnerabilities/79140
- WEB https://launchpad.net/swift/+milestone/1.7.0
- PACKAGE https://opendev.org/openstack/swift
- WEB https://web.archive.org/web/20130629092623/http://www.securityfocus.com/bid/55420
- WEB http://lists.fedoraproject.org/pipermail/package-announce/2012-October/089472.html
- WEB http://rhn.redhat.com/errata/RHSA-2012-1379.html
- WEB http://rhn.redhat.com/errata/RHSA-2013-0691.html
- WEB http://www.openwall.com/lists/oss-security/2012/09/05/16
- WEB http://www.openwall.com/lists/oss-security/2012/09/05/4
- WEB http://www.securityfocus.com/bid/55420
Ready to move
Start Securing
Free, no credit card | First findings in minutes