Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXhycjQtNzRtYy1ycGpj

Pyro mishandles pid files in temporary directory locations and opening the pid file as root

pyro before 3.15 unsafely handles pid files in temporary directory locations and opening the pid file as root. An attacker can use this flaw to overwrite arbitrary files via symlinks.

Permalink: https://github.com/advisories/GHSA-xrr4-74mc-rpjc
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXhycjQtNzRtYy1ycGpj
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: over 6 years ago
Updated: about 1 month ago


CVSS Score: 7.5
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Identifiers: GHSA-xrr4-74mc-rpjc, CVE-2011-2765
References: Repository: https://github.com/irmen/Pyro3
Blast Radius: 7.8

Affected Packages

pypi:pyro
Dependent packages: 4
Dependent repositories: 11
Downloads: 2,177 last month
Affected Version Ranges: < 3.15
Fixed in: 3.15
All affected versions: 3.9.1
All unaffected versions: