First published: Wed Sep 05 2012(Updated: )
OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Swift | <=1.6.0 | |
OpenStack Swift | =1.0.0 | |
OpenStack Swift | =1.0.1 | |
OpenStack Swift | =1.0.2 | |
OpenStack Swift | =1.1.0 | |
OpenStack Swift | =1.1.0-rc1 | |
OpenStack Swift | =1.1.0-rc2 | |
OpenStack Swift | =1.2.0 | |
OpenStack Swift | =1.2.0-gamma1 | |
OpenStack Swift | =1.2.0-rc1 | |
OpenStack Swift | =1.3.0 | |
OpenStack Swift | =1.3.0-gamma1 | |
OpenStack Swift | =1.3.0-rc1 | |
OpenStack Swift | =1.4.0 | |
OpenStack Swift | =1.4.1 | |
OpenStack Swift | =1.4.2 | |
OpenStack Swift | =1.4.3 | |
OpenStack Swift | =1.4.4 | |
OpenStack Swift | =1.4.5 | |
OpenStack Swift | =1.4.6 | |
OpenStack Swift | =1.4.7 | |
OpenStack Swift | =1.4.8 | |
OpenStack Swift | =1.5.0 | |
OpenStack Swift | <1.7.0 | |
Fedoraproject Fedora | =16 | |
Redhat Gluster Storage Management Console | =2.0 | |
Redhat Gluster Storage Server For On-premise | =2.0 | |
Redhat Storage | =2.0 | |
Redhat Storage For Public Cloud | =2.0 | |
Redhat Enterprise Linux Server | =5.0 | |
Redhat Enterprise Linux Server | =6.0 | |
pip/swift | <1.7.0 | 1.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.