CVE-2013-5093
Publication date 27 September 2013
Last updated 24 July 2024
Ubuntu priority
The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object.
Status
Package | Ubuntu Release | Status |
---|---|---|
graphite-web | 13.04 raring | Not in release |
12.10 quantal | Not in release | |
12.04 LTS precise | Not in release | |
10.04 LTS lucid | Not in release |
Notes
seth-arnold
upstream 0.9.12 includes some XSS fixes that don’t (yet?) have a CVE entry; a full update might be better.