Piston And Tastypie Remote Code Execution Vulnerability
BID:50477
Info
Piston And Tastypie Remote Code Execution Vulnerability
| Bugtraq ID: | 50477 |
| Class: | Unknown |
| CVE: |
CVE-2011-4103 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 02 2011 12:00AM |
| Updated: | Nov 15 2011 12:52AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Django Tastypie 0.9.9 Django Tastypie 0.9 Django Piston 0.2.2 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
Django Tastypie 0.9.10 Django Piston 0.2.3 Django Piston 0.2.2.1 |
Discussion
Piston And Tastypie Remote Code Execution Vulnerability
Piston and Tastypie is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Piston versions 0.2.2.x prior to 0.2.2.1 and Tastypie versions 0.9.x prior to 0.9.10 are vulnerable.
Piston and Tastypie is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Piston versions 0.2.2.x prior to 0.2.2.1 and Tastypie versions 0.9.x prior to 0.9.10 are vulnerable.
Exploit / POC
Piston And Tastypie Remote Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Piston And Tastypie Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Piston And Tastypie Remote Code Execution Vulnerability
References:
References:
- Piston and Tastypie security releases issued (Django)
- Piston Homepage (Django)
- Tastypie Homepage (Django)