Python Pickle Class Constructor Arbitrary Code Execution Vulnerability
BID:5257
Info
Python Pickle Class Constructor Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 5257 |
| Class: | Design Error |
| CVE: | |
| Remote: | Unknown |
| Local: | Unknown |
| Published: | Jul 17 2002 12:00AM |
| Updated: | Jul 17 2002 12:00AM |
| Credit: | Published by Jeff Epler <[email protected]>. |
| Vulnerable: |
Python Software Foundation Python 2.1.3 Python Software Foundation Python 2.1.2 Python Software Foundation Python 2.1.1 Python Software Foundation Python 2.1 Python Software Foundation Python 2.0.1 Python Software Foundation Python 2.0 Python Software Foundation Python 1.6.1 Python Software Foundation Python 1.6 Python Software Foundation Python 1.5.2 |
| Not Vulnerable: |
Python Software Foundation Python 2.2.1 Python Software Foundation Python 2.2 |
Discussion
Python Pickle Class Constructor Arbitrary Code Execution Vulnerability
Python is an open source, object oriented programming language. The Python Pickle module is provided to convert object variables into a serialized form ("pickling"), and later recover the data back into an object hierarchy ("unpickling").
A vulnerability has been reported in the Pickle implementation included with some versions of Python. If specially crafted malicious object data is "unpickled", it may cause arbitrary Python commands to be executed, including system calls. This is accomplished by specifying an available function as the class constructor.
Exploitation of this vulnerability will be highly dependent on a specific Python application which accepts a pickle string from an untrusted source. This behavior has been reported in some implementations of the Python SmartCookie class.
Python is an open source, object oriented programming language. The Python Pickle module is provided to convert object variables into a serialized form ("pickling"), and later recover the data back into an object hierarchy ("unpickling").
A vulnerability has been reported in the Pickle implementation included with some versions of Python. If specially crafted malicious object data is "unpickled", it may cause arbitrary Python commands to be executed, including system calls. This is accomplished by specifying an available function as the class constructor.
Exploitation of this vulnerability will be highly dependent on a specific Python application which accepts a pickle string from an untrusted source. This behavior has been reported in some implementations of the Python SmartCookie class.