9.8
CVE-2012-4406
- EPSS 6.52%
- Veröffentlicht 22.10.2012 23:55:06
- Zuletzt bearbeitet 16.06.2026 23:44:57
- Erkennungen
OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ Fedora Version 16
Redhat ≫ Gluster Storage Management Console Version 2.0
Redhat ≫ Gluster Storage Server For On-premise Version 2.0
Redhat ≫ Storage For Public Cloud Version 2.0
Redhat ≫ Enterprise Linux Server Version 5.0
Redhat ≫ Enterprise Linux Server Version 6.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 6.52% | 0.929 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
http://lists.fedoraproject.org/pipermail/package-announce/2012-October/089472.html
http://rhn.redhat.com/errata/RHSA-2012-1379.html
http://rhn.redhat.com/errata/RHSA-2013-0691.html
http://www.openwall.com/lists/oss-security/2012/09/05/16
http://www.openwall.com/lists/oss-security/2012/09/05/4
http://www.securityfocus.com/bid/55420
https://bugs.launchpad.net/swift/+bug/1006414
https://bugzilla.redhat.com/show_bug.cgi?id=854757
https://exchange.xforce.ibmcloud.com/vulnerabilities/79140
https://github.com/openstack/swift/commit/e1ff51c04554d51616d2845f92ab726cb0e5831a
https://launchpad.net/swift/+milestone/1.7.0