Vulnerability Bulletins

DSA-3013 s3ql - security update

   
Affected software Debian
 
Nikolaus Rath discovered that s3ql, a file system for online datastorage, used the pickle functionality of the Python programminglanguage in an unsafe way. As a result, a malicious storage backendor man-in-the-middle attacker was able execute arbitrary code.

More info:

https://www.debian.org/security/2014/dsa-3013