#4433 NORM 8.2.0 (: Potential for arbitrary code execution due to use of sharedstate/pickle

Zarro Boogs per Child bugtracker at laptop.org
Thu Dec 25 10:30:31 EST 2008


#4433: Potential for arbitrary code execution due to use of sharedstate/pickle
-------------------------------------------+--------------------------------
           Reporter:  smcv                 |       Owner:  rwh                 
               Type:  defect               |      Status:  closed              
           Priority:  normal               |   Milestone:  8.2.0 (was Update.2)
          Component:  calculator-activity  |     Version:                      
         Resolution:  fixed                |    Keywords:  collaboration       
        Next_action:  never set            |    Verified:  0                   
Deployment_affected:                       |   Blockedby:                      
           Blocking:                       |  
-------------------------------------------+--------------------------------
Changes (by rwh):

  * status:  new => closed
  * next_action:  => never set
  * resolution:  => fixed


Comment:

 I removed the sharedstate module in v26 and replaced it by some quite
 generic code in shareable_activity.py; this might be usable for other
 activities as well.

-- 
Ticket URL: <http://dev.laptop.org/ticket/4433#comment:6>
One Laptop Per Child <http://laptop.org/>
OLPC bug tracking system


More information about the Bugs mailing list