Описание
Cheetah Path Search Order Hijacking
Cheetah 0.9.15 and 0.9.16 searches the /tmp
directory for modules before using the paths in the PYTHONPATH
variable, which allows local users to execute arbitrary code via a malicious module in /tmp/
.
Пакеты
Наименование
cheetah
pip
Затронутые версииВерсия исправления
>= 0.9.15, <= 0.9.16
Отсутствует
Связанные уязвимости
nvd
больше 20 лет назад
Cheetah 0.9.15 and 0.9.16 searches the /tmp directory for modules before using the paths in the PYTHONPATH variable, which allows local users to execute arbitrary code via a malicious module in /tmp/.
debian
больше 20 лет назад
Cheetah 0.9.15 and 0.9.16 searches the /tmp directory for modules befo ...