CVE-2011-2520
Publication date 21 July 2011
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the backend, which might allow local users to gain privileges via a crafted serialized object.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| system-config-printer | ||
Notes
mdeslaur
This is actually a flaw in the system-config-firewall backend. system-config-printer opens pickles from the backend, but since we don't ship the backend (system-config-firewall), we're not affected.
Severity score breakdown
CVSS version: CVSS v3.0
Base score
7.8 · High
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H