VulnerabilityModified
CVE-2011-2765
pyro before 3.15 unsafely handles pid files in temporary directory locations and opening the pid file as root.
HIGH 7.5EPSS 2.21%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.21%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
pyro before 3.15 unsafely handles pid files in temporary directory locations and opening the pid file as root. An attacker can use this flaw to overwrite arbitrary files via symlinks.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 2.21% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-59
- Affected
- pyro project/pyro
- Source
- cve@mitre.org
References
- https://bugs.debian.org/631912Exploit, Issue Tracking, Third Party Advisory
- https://github.com/irmen/Pyro3/commit/554e095a62c4412c91f981e72fd34a936ac2bf1eThird Party Advisory
- https://pythonhosted.org/Pyro/12-changes.htmlVendor Advisory
- https://bugs.debian.org/631912Exploit, Issue Tracking, Third Party Advisory
- https://github.com/irmen/Pyro3/commit/554e095a62c4412c91f981e72fd34a936ac2bf1eThird Party Advisory
- https://pythonhosted.org/Pyro/12-changes.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.