CVE-2014-0485 Information
Feb 14, 2021
cve
Description
S3QL 1.18.1 and earlier uses the pickle Python module unsafely which allows remote attackers to execute arbitrary code via a crafted serialized object in (1) common.py or (2) local.py in backends/.
Reference
http://www.debian.org/security/2014/dsa-3013 http://www.openwall.com/lists/oss-security/2014/08/28/3 https://bitbucket.org/nikratio/s3ql/commits/091ac263809b4e8
Share on: