CVE-2011-2765

HIGH

Pyro < 3.15 - Arbitrary File Write via Symlink Attack on PID File

Title source: llm
STIX 2.1

Description

pyro before 3.15 unsafely handles pid files in temporary directory locations and opening the pid file as root. An attacker can use this flaw to overwrite arbitrary files via symlinks.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
https://pythonhosted.org/Pyro/12-changes.html
Exploit, Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugs.debian.org/631912

Scores

CVSS v3 7.5
EPSS 0.0219
EPSS Percentile 80.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-59
Status published
Products (2)
pypi/pyro 0 - 3.15PyPI
pyro_project/pyro < 3.15
Published Aug 20, 2018
Tracked Since Feb 18, 2026