Py2Play Object Unpickling Remote Python Code Execution Vulnerability
BID:14864
Info
Py2Play Object Unpickling Remote Python Code Execution Vulnerability
| Bugtraq ID: | 14864 |
| Class: | Design Error |
| CVE: |
CVE-2005-2875 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 17 2005 12:00AM |
| Updated: | Sep 07 2006 03:33PM |
| Credit: | Discovery is credited to Arc Riley. |
| Vulnerable: |
Py2Play Py2Play 0.1.7 |
| Not Vulnerable: | |
Discussion
Py2Play Object Unpickling Remote Python Code Execution Vulnerability
Py2Play is prone to a vulnerability that may let remote attackers execute arbitrary Python code in the context of the program.
Remote peers may exploit this issue.
Py2Play is prone to a vulnerability that may let remote attackers execute arbitrary Python code in the context of the program.
Remote peers may exploit this issue.
Exploit / POC
Py2Play Object Unpickling Remote Python Code Execution Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Py2Play Object Unpickling Remote Python Code Execution Vulnerability
Solution:
The vendor has released version 0.1.8 to address this issue. Please see the references and associated advisories for more information.
Py2Play Py2Play 0.1.7
Solution:
The vendor has released version 0.1.8 to address this issue. Please see the references and associated advisories for more information.
Py2Play Py2Play 0.1.7
-
Debian python-2play_0.1.7-1sarge1_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/p/py2play/python-2play_0. 1.7-1sarge1_all.deb
References
Py2Play Object Unpickling Remote Python Code Execution Vulnerability
References:
References:
- SoyaWiki Front Page (SoyaWiki)