gedit: untrusted python modules search path
Published Jan 28, 2009
6.9
MEDIUMCVSS 2.0
EPSS 0.62%
Description
Untrusted search path vulnerability in the Python module in gedit allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).
Affected products
No data.
Configuration 2
- 9
No data.
Red Hat Enterprise Linux 5
gedit
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | gedit | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect gedit as shipped in Red Hat Enterprise Linux 3 and 4. It does affect gedit in Red Hat Enterprise Linux 5. Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
References (14)
- http://bugzilla.gnome.org/show_bug.cgi?id=569214 x_refsource_MISCExploitIssue TrackingPatchVendor Advisory
- http://secunia.com/advisories/33759 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/33769 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/34522 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://security.gentoo.org/glsa/glsa-200903-41.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:039 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.openwall.com/lists/oss-security/2009/01/26/2 mailing-listx_refsource_MLISTMailing List
- http://www.securityfocus.com/bid/33445 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2009-0314 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=481556 x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48271 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2009-0314
- https://www.cve.org/CVERecord?id=CVE-2009-0314
- https://www.redhat.com/archives/fedora-package-announce/2009-January/msg01195.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
Change history (0)
No recorded changes yet.