CVE-2007-5741: Code Injection
Published Nov 7, 2007
·Updated
Plone 2.5 through 2.5.4 and 3.0 through 3.0.2 allows remote attackers to execute arbitrary Python code via network data containing pickled objects for the (1) statusmessages or (2) linkintegrity module, which the module unpickles and executes.
Affected Software
10 affected componentsFixes available
pip/plone>=3.0<=3.0.2
3.0.3
pip/plone>=2.5<=2.5.4
2.5.5
Plone plone=2.5
Plone plone=2.5.1
Plone plone=2.5.1_rc
Plone plone=2.5.4
Plone plone=2.5_beta1
Plone plone=3.0
Plone plone=3.0.1
Plone plone=3.0.2
Remediation
Patch Available
Patch Available
Event History
Nov 7, 2007
CVE Published
via NVD·09:46 PM
Nov 8, 2007
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
May 1, 2022
Advisory Published
via GitHub·06:36 PM
Frequently Asked Questions
1
What is the severity of CVE-2007-5741?
CVE-2007-5741 is considered a critical vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2007-5741?
To fix CVE-2007-5741, upgrade Plone to version 2.5.5 or 3.0.3.
3
What versions of Plone are affected by CVE-2007-5741?
CVE-2007-5741 affects Plone versions 2.5 through 2.5.4 and 3.0 through 3.0.2.
4
What kind of attack can exploit CVE-2007-5741?
CVE-2007-5741 can be exploited by sending crafted network data containing pickled objects to execute arbitrary Python code.
5
Is CVE-2007-5741 a local or remote vulnerability?
CVE-2007-5741 is a remote vulnerability, allowing attackers to exploit it over a network.