Revision Date: | 2014-06-23 | Version: | 19 |
Title: | DSA-2344-1 python-django-piston -- deserialization vulnerability |
Description: | It was discovered that the Piston framework can deserializes untrusted YAML and Pickle data, leading to remote code execution. The old stable distribution does not contain a python-django-piston package. |
Family: | unix | Class: | patch |
Status: | ACCEPTED | Reference(s): | CVE-2011-4103 DSA-2344-1
|
Platform(s): | Debian GNU/kFreeBSD 6.0 Debian GNU/Linux 6.0
| Product(s): | python-django-piston
|
Definition Synopsis |
Debian 6.0 is installed AND GNU/Linux or GNU/kFreeBSD kernel
Debian GNU/Linux is installed
OR Debian GNU/kFreeBSD is installed
AND Installed architecture is all
AND python-django-piston DPKG is earlier than 0.2.2-1+squeeze1
|