LWN.net Logo

xchat: arbitrary code execution

Package(s):xchat CVE #(s):CVE-2009-0315
Created:March 2, 2009 Updated:December 9, 2009
Description:

From the Mandriva advisory:

Python has a variable called sys.path that contains all paths where Python loads modules by using import scripting procedure. A wrong handling of that variable enables local attackers to execute arbitrary code via Python scripting in the current X-Chat working directory (CVE-2009-0315).

Alerts:
Mandriva MDVSA-2009:059-1 2009-12-08
Mandriva MDVSA-2009:059 2009-02-27

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds