Описание
Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory.
Ссылки
- Mailing ListThird Party Advisory
 - Not Applicable
 - Not Applicable
 - Not Applicable
 - Not Applicable
 - Not Applicable
 - Not Applicable
 - Not Applicable
 - Third Party Advisory
 - Third Party Advisory
 - Broken Link
 - Mailing ListThird Party Advisory
 - Mailing ListThird Party Advisory
 - Mailing ListThird Party Advisory
 - Third Party Advisory
 - Third Party Advisory
 - Third Party Advisory
 - Third Party Advisory
 - Third Party Advisory
 
Уязвимые конфигурации
Одно из
Одно из
EPSS
6.9 Medium
CVSS2
Дефекты
Связанные уязвимости
Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory.
Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory.
Untrusted search path vulnerability in the PySys_SetArgv API function ...
Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory.
ELSA-2011-0027: python security, bug fix, and enhancement update (LOW)
EPSS
6.9 Medium
CVSS2