CVE-2011-2765

NameCVE-2011-2765
Descriptionpyro before 3.15 unsafely handles pid files in temporary directory locations and opening the pid file as root. An attacker can use this flaw to overwrite arbitrary files via symlinks.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs631912

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
pyro (PTS)buster1:3.16-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
pyrosource(unstable)1:3.14-1low631912

Notes

[lenny] - pyro <no-dsa> (Minor issue)
[squeeze] - pyro <no-dsa> (Minor issue)
https://github.com/irmen/Pyro3/commit/554e095a62c4412c91f981e72fd34a936ac2bf1e

Search for package or bug name: Reporting problems