irmen/Pyro3

irmen/Pyro3

Releases12
Frequency1 month 2 weeks
Last Release
Stars4
Pyro 3.x (old version - unmaintained - use Pyro4 instead)

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL

An issue in the <code>pickle</code> protocol of Pyro v3.x allows attackers to execute arbitrary code via supplying a crafted pickled string message.

5 MEDIUM

pyro before 3.15 unsafely handles pid files in temporary directory locations and opening the pid file as root. An attacker can use this flaw to overwrite arbitrary files via symlinks.