DEBIAN-CVE-2011-4104

Source
https://security-tracker.debian.org/tracker/CVE-2011-4104
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2011-4104.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2011-4104
Upstream
Published
2014-10-27T01:55:23Z
Modified
2026-09-14T06:47:32Z
Summary
[none]
Details

The from_yaml method in serializers.py in Django Tastypie before 0.9.10 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vectors related to the yaml.load method.

References

Affected packages

Debian:12 / django-tastypie

Package

Name
django-tastypie
Purl
pkg:deb/debian/django-tastypie?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.9.10-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2011-4104.json"

Debian:13 / django-tastypie

Package

Name
django-tastypie
Purl
pkg:deb/debian/django-tastypie?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.9.10-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2011-4104.json"

Debian:14 / django-tastypie

Package

Name
django-tastypie
Purl
pkg:deb/debian/django-tastypie?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.9.10-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2011-4104.json"