CVE-2014-0485

S3QL <1.18.1 - Code Injection

Title source: llm
STIX 2.1

Description

S3QL 1.18.1 and earlier uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object in (1) common.py or (2) local.py in backends/.

References (3)

Core 3
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2014/dsa-3013
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/08/28/3

Scores

EPSS 0.0160
EPSS Percentile 81.9%

Details

CWE
CWE-94
Status published
Products (3)
s3ql_project/s3ql 1.17
s3ql_project/s3ql 1.18
s3ql_project/s3ql < 1.18.1
Published Sep 02, 2014
Tracked Since Feb 18, 2026