Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 00:55
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042751.html - Mailing List, Third Party Advisory | |
References | () http://secunia.com/advisories/34522 - Not Applicable | |
References | () http://secunia.com/advisories/40194 - Not Applicable | |
References | () http://secunia.com/advisories/42888 - Not Applicable | |
References | () http://secunia.com/advisories/50858 - Not Applicable | |
References | () http://secunia.com/advisories/51024 - Not Applicable | |
References | () http://secunia.com/advisories/51040 - Not Applicable | |
References | () http://secunia.com/advisories/51087 - Not Applicable | |
References | () http://security.gentoo.org/glsa/glsa-200903-41.xml - Third Party Advisory | |
References | () http://security.gentoo.org/glsa/glsa-200904-06.xml - Third Party Advisory | |
References | () http://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg586010.html - | |
References | () http://www.nabble.com/Bug-484305%3A-bicyclerepair%3A-bike.vim-imports-untrusted-python-files-from-cwd-td18848099.html - Broken Link | |
References | () http://www.openwall.com/lists/oss-security/2009/01/26/2 - Mailing List, Third Party Advisory | |
References | () http://www.openwall.com/lists/oss-security/2009/01/28/5 - Mailing List, Third Party Advisory | |
References | () http://www.openwall.com/lists/oss-security/2009/01/30/2 - Mailing List, Third Party Advisory | |
References | () http://www.redhat.com/support/errata/RHSA-2011-0027.html - Third Party Advisory | |
References | () http://www.ubuntu.com/usn/USN-1596-1 - Third Party Advisory | |
References | () http://www.ubuntu.com/usn/USN-1613-1 - Third Party Advisory | |
References | () http://www.ubuntu.com/usn/USN-1613-2 - Third Party Advisory | |
References | () http://www.ubuntu.com/usn/USN-1616-1 - Third Party Advisory | |
References | () http://www.vupen.com/english/advisories/2010/1448 - Permissions Required | |
References | () http://www.vupen.com/english/advisories/2011/0122 - Permissions Required | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=482814 - Issue Tracking, Third Party Advisory |
05 Jul 2022, 18:57
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:python_software_foundation:python:2.1.3:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.5.1:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.4.2:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.2.3:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.3.2:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.4.1:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.0:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:1.6:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.3.5:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.2:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.3.4:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:1.6.1:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.2.2:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.5.4:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.3:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.3.7:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.0.1:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:*:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.3.6:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.1.2:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.3.1:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.5.2:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.4.5:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.1:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.4.4:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.5:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.1.1:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.4.3:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:1.5.2:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.2.1:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.4:*:*:*:*:*:*:* cpe:2.3:a:python_software_foundation:python:2.3.3:*:*:*:*:*:*:* |
cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:* cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:* cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:* cpe:2.3:a:python:python:*:*:*:*:*:*:*:* cpe:2.3:o:canonical:ubuntu_linux:11.04:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:13:*:*:*:*:*:*:* |
References | (SECUNIA) http://secunia.com/advisories/34522 - Not Applicable | |
References | (SECUNIA) http://secunia.com/advisories/40194 - Not Applicable | |
References | (SECUNIA) http://secunia.com/advisories/42888 - Not Applicable | |
References | (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=482814 - Issue Tracking, Third Party Advisory | |
References | (MLIST) http://www.mail-archive.com/debian-bugs-dist@lists.debian.org/msg586010.html - Patch, Third Party Advisory | |
References | (SECUNIA) http://secunia.com/advisories/50858 - Not Applicable | |
References | (MLIST) http://www.openwall.com/lists/oss-security/2009/01/26/2 - Mailing List, Third Party Advisory | |
References | (VUPEN) http://www.vupen.com/english/advisories/2010/1448 - Permissions Required | |
References | (MLIST) http://www.openwall.com/lists/oss-security/2009/01/28/5 - Mailing List, Third Party Advisory | |
References | (UBUNTU) http://www.ubuntu.com/usn/USN-1596-1 - Third Party Advisory | |
References | (SECUNIA) http://secunia.com/advisories/51087 - Not Applicable | |
References | (GENTOO) http://security.gentoo.org/glsa/glsa-200903-41.xml - Third Party Advisory | |
References | (MLIST) http://www.nabble.com/Bug-484305%3A-bicyclerepair%3A-bike.vim-imports-untrusted-python-files-from-cwd-td18848099.html - Broken Link | |
References | (SECUNIA) http://secunia.com/advisories/51024 - Not Applicable | |
References | (REDHAT) http://www.redhat.com/support/errata/RHSA-2011-0027.html - Third Party Advisory | |
References | (UBUNTU) http://www.ubuntu.com/usn/USN-1613-2 - Third Party Advisory | |
References | (SECUNIA) http://secunia.com/advisories/51040 - Not Applicable | |
References | (GENTOO) http://security.gentoo.org/glsa/glsa-200904-06.xml - Third Party Advisory | |
References | (VUPEN) http://www.vupen.com/english/advisories/2011/0122 - Permissions Required | |
References | (MLIST) http://www.openwall.com/lists/oss-security/2009/01/30/2 - Mailing List, Third Party Advisory | |
References | (FEDORA) http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042751.html - Mailing List, Third Party Advisory | |
References | (UBUNTU) http://www.ubuntu.com/usn/USN-1613-1 - Third Party Advisory | |
References | (UBUNTU) http://www.ubuntu.com/usn/USN-1616-1 - Third Party Advisory | |
CWE | CWE-426 |
Information
Published : 2009-01-28 02:30
Updated : 2024-11-21 00:55
NVD link : CVE-2008-5983
Mitre link : CVE-2008-5983
CVE.ORG link : CVE-2008-5983
JSON object : View
Products Affected
fedoraproject
- fedora
python
- python
canonical
- ubuntu_linux
CWE
CWE-426
Untrusted Search Path