Vulnerability Name: | CVE-2009-0314 (CCN-48271) | ||||||||
Assigned: | 2009-01-26 | ||||||||
Published: | 2009-01-26 | ||||||||
Updated: | 2020-06-15 | ||||||||
Summary: | Untrusted search path vulnerability in the Python module in gedit allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983). | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C) 5.1 Medium (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.1 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-426 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MISC Type: Exploit, Issue Tracking, Patch, Vendor Advisory http://bugzilla.gnome.org/show_bug.cgi?id=569214 Source: MITRE Type: CNA CVE-2009-0314 Source: CCN Type: gedit Web page gedit Source: CCN Type: SA33759 GNOME gedit Insecure Python Module Search Path Vulnerability Source: SECUNIA Type: Third Party Advisory 33759 Source: SECUNIA Type: Third Party Advisory 33769 Source: SECUNIA Type: Third Party Advisory 34522 Source: GENTOO Type: Third Party Advisory GLSA-200903-41 Source: CCN Type: GLSA-200903-41 gedit: Untrusted search path Source: MANDRIVA Type: Third Party Advisory MDVSA-2009:039 Source: MLIST Type: Mailing List [oss-security] 20090126 CVE request -- Python < 2.6 PySys_SetArgv issues (epiphany, csound, dia, eog, gedit, xchat, vim, nautilus-python, Gnumeric) Source: BID Type: Third Party Advisory, VDB Entry 33445 Source: CCN Type: BID-33445 gedit 'PySys_SetArgv' Remote Command Execution Vulnerability Source: CCN Type: FEDORA-2009-1189 gedit-2.22.3-3.fc9 security update Source: CCN Type: Red Hat Bugzilla Bug 481556 gedit: untrusted python modules search path Source: CONFIRM Type: Exploit, Issue Tracking, Patch, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=481556 Source: XF Type: Third Party Advisory, VDB Entry gedit-pysyssetargv-privilege-escalation(48271) Source: XF Type: UNKNOWN gedit-pysyssetargv-privilege-escalation(48271) Source: FEDORA Type: Third Party Advisory FEDORA-2009-1189 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: ![]() | ||||||||
BACK |