fw_dbus.py in system-config-firewall 1.2.29 and earlier...
Moderate severity
Unreviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Jan 21, 2024
Description
Published by the National Vulnerability Database
Jul 21, 2011
Published to the GitHub Advisory Database
May 17, 2022
Last updated
Jan 21, 2024
fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the backend, which might allow local users to gain privileges via a crafted serialized object.
References