Description
S3QL 1.18.1 and earlier uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object in (1) common.py or (2) local.py in backends/.
References (3)
Core 3
Core References
Exploit, Patch x_refsource_confirm
https://bitbucket.org/nikratio/s3ql/commits/091ac263809b4e8
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2014/dsa-3013
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/08/28/3
Scores
EPSS
0.0160
EPSS Percentile
81.9%
Details
CWE
CWE-94
Status
published
Products (3)
s3ql_project/s3ql
1.17
s3ql_project/s3ql
1.18
s3ql_project/s3ql
< 1.18.1
Published
Sep 02, 2014
Tracked Since
Feb 18, 2026