|
|
| |
|
| |
xchat: arbitrary code execution
| Package(s): | xchat |
CVE #(s): | CVE-2009-0315
|
| Created: | March 2, 2009 |
Updated: | December 9, 2009 |
| Description: |
From the Mandriva advisory:
Python has a variable called sys.path that contains all paths where
Python loads modules by using import scripting procedure. A wrong
handling of that variable enables local attackers to execute arbitrary
code via Python scripting in the current X-Chat working directory
(CVE-2009-0315).
|
| Alerts: |
|
( Log in to post comments)
|
|
|