Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Gentoo Linux Security Advisory GLSA 200509-09
https://security.gentoo.org/
Severity: High
Title: Py2Play: Remote execution of arbitrary Python code
Date: September 17, 2005
Bugs: #103524
ID: 200509-09
Synopsis
=======
A design error in Py2Play allows attackers to execute arbitrary code.
Background
=========
Py2Play is a peer-to-peer network game engine written in Python.
Pickling is a Python feature allowing to serialize Python objects into
string representations (called pickles) that can be sent over the
network.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 dev-python/py2play <= 0.1.7 Vulnerable!
-------------------------------------------------------------------
NOTE: Certain packages are still vulnerable. Users should migrate
to another package if one is available or wait for the
existing packages to be marked stable by their
architecture maintainers.
==========
Arc Riley discovered that Py2Play uses Python pickles to send objects
over a peer-to-peer ...
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.