7.5
CVSSv2

CVE-2012-4406

Published: 22/10/2012 Updated: 25/01/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

OpenStack Object Storage (swift) prior to 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote malicious users to execute arbitrary code via a crafted pickle object.

Vulnerable Product Search on Vulmon Subscribe to Product

openstack swift

fedoraproject fedora 16

redhat enterprise linux server 5.0

redhat enterprise linux server 6.0

redhat storage 2.0

redhat storage for public cloud 2.0

redhat gluster storage server for on-premise 2.0

redhat gluster storage management console 2.0

Vendor Advisories

Debian Bug report logs - #686812 swift: CVE-2012-4406 Package: swift; Maintainer for swift is Debian OpenStack <team+openstack@trackerdebianorg>; Source for swift is src:swift (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Thu, 6 Sep 2012 07:15:02 UTC Severity: grave Tags: security ...
Multiple security issues were fixed in OpenStack Swift ...
Synopsis Important: openstack-swift security update Type/Severity Security Advisory: Important Topic Updated openstack-swift packages that fix one security issue are nowavailable for Red Hat OpenStack EssexThe Red Hat Security Response Team has rated this update as havingimportant security impact A Common ...
Synopsis Important: Red Hat Storage 20 security, bug fix, and enhancement update #4 Type/Severity Security Advisory: Important Topic Updated Red Hat Storage 20 packages that fix multiple security issues,several bugs, and add enhancements are now availableThe Red Hat Security Response Team has rated this ...