New submission from Jan Lieskovsky <ian...@seznam.cz>: Common Vulnerabilities and Exposures assigned an identifier CVE-2008-5983 (and related CVE ids) to the following vulnerability:
Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory. References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5983 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-5983 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5984 https://bugzilla.redhat.com/show_bug.cgi?id=481551 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5985 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5986 https://bugzilla.redhat.com/show_bug.cgi?id=481550 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5987 https://bugzilla.redhat.com/show_bug.cgi?id=481553 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0314 http://bugzilla.gnome.org/show_bug.cgi?id=569214 https://bugzilla.redhat.com/show_bug.cgi?id=481556 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0315 https://bugzilla.redhat.com/show_bug.cgi?id=481560 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0316 https://bugzilla.redhat.com/show_bug.cgi?id=481565 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0317 https://bugzilla.redhat.com/show_bug.cgi?id=481570 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0318 https://bugzilla.redhat.com/show_bug.cgi?id=481572 ---------- components: Interpreter Core files: python-CVE-2009-5983.patch keywords: patch messages: 85965 nosy: iankko severity: normal status: open title: CVE-2008-5983 python: untrusted python modules search path type: security versions: Python 3.1 Added file: http://bugs.python.org/file13685/python-CVE-2009-5983.patch _______________________________________ Python tracker <rep...@bugs.python.org> <http://bugs.python.org/issue5753> _______________________________________ _______________________________________________ Python-bugs-list mailing list Unsubscribe: http://mail.python.org/mailman/options/python-bugs-list/archive%40mail-archive.com