gedit: arbitrary code execution via Python scripts
| Package(s): | gedit | CVE #(s): | CVE-2009-0314 | ||||||||
| Created: | February 16, 2009 | Updated: | March 31, 2009 | ||||||||
| Description: | From the Mandriva advisory: Python has a variable called sys.path that contains all paths where Python loads modules by using import scripting procedure. A wrong handling of that variable enables local attackers to execute arbitrary code via Python scripting in the current gedit working directory | ||||||||||
| Alerts: |
| ||||||||||
