fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the backend, which might allow local users to gain privileges via a crafted serialized object.
2011-07-21T23:55:03.410
2025-04-11T00:51:21.963
Deferred
CVSSv3.1: 7.8 (HIGH)
AV:L/AC:H/Au:S/C:C/I:C/A:C
1.5
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | system-config-firewall | ≤ 1.2.29 | Yes |
Operating System | fedoraproject | fedora | 15 | Yes |