DSA-2344-1 python-django-piston -- deserialization vulnerability

Related Vulnerabilities: CVE-2011-4103  

It was discovered that the Piston framework can deserializes untrusted YAML and Pickle data, leading to remote code execution (CVE-2011-4103). The old stable distribution (lenny) does not contain a python-django-piston package. For the stable distribution (squeeze), this problem has been fixed in version 0.2.2-1+squeeze1. For the testing distribution (wheezy) and the unstable distribution (sid), this problem has been fixed in version 0.2.2-2. We recommend that you upgrade your python-django-piston packages.

Debian Security Advisory

DSA-2344-1 python-django-piston -- deserialization vulnerability

Date Reported:
11 Nov 2011
Affected Packages:
python-django-piston
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 647315.
In Mitre's CVE dictionary: CVE-2011-4103.
More information:

It was discovered that the Piston framework can deserializes untrusted YAML and Pickle data, leading to remote code execution (CVE-2011-4103).

The old stable distribution (lenny) does not contain a python-django-piston package.

For the stable distribution (squeeze), this problem has been fixed in version 0.2.2-1+squeeze1.

For the testing distribution (wheezy) and the unstable distribution (sid), this problem has been fixed in version 0.2.2-2.

We recommend that you upgrade your python-django-piston packages.