Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2008-5983

Опубликовано: 06 авг. 2008
Источник: redhat
CVSS2: 3.7

Описание

Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=482814python: untrusted python modules search path

3.7 Low

CVSS2

Связанные уязвимости

ubuntu
больше 16 лет назад

Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory.

nvd
больше 16 лет назад

Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory.

debian
больше 16 лет назад

Untrusted search path vulnerability in the PySys_SetArgv API function ...

github
около 3 лет назад

Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory.

oracle-oval
больше 14 лет назад

ELSA-2011-0027: python security, bug fix, and enhancement update (LOW)

3.7 Low

CVSS2