[Bug 1173583] New: VUL-0: CVE-2013-7489: python-beaker: Deserialization of Untrusted Data which can lead to Arbitrary code execution
http://bugzilla.opensuse.org/show_bug.cgi?id=1173583 Bug ID: 1173583 Summary: VUL-0: CVE-2013-7489: python-beaker: Deserialization of Untrusted Data which can lead to Arbitrary code execution Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.1 Hardware: Other URL: https://smash.suse.de/issue/262406/ OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: mcepl@suse.com Reporter: atoptsoglou@suse.com QA Contact: security-team@suse.de Found By: Security Response Team Blocker: --- CVE-2013-7489 python-beaker is affected by Deserialization of untrusted data which could lead to Arbitrary code execution. References: https://github.com/bbangert/beaker/issues/191 https://www.openwall.com/lists/oss-security/2020/05/14/11 References: https://bugzilla.redhat.com/show_bug.cgi?id=1850105 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-7489 https://www.openwall.com/lists/oss-security/2020/05/14/11 http://people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-7489.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7489 https://github.com/bbangert/beaker/issues/191 -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1173583 Alexandros Toptsoglou <atoptsoglou@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |pgajdos@suse.com -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1173583 http://bugzilla.opensuse.org/show_bug.cgi?id=1173583#c2 --- Comment #2 from Alexandros Toptsoglou <atoptsoglou@suse.com> --- This is still an open issue. Useful discussion in the upstream bug. One suggested approach is signing of the cache data upon commit to the database to be verified upon retrieval. -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com