CVE-2008-5983 PUBLISHED CVSS 6.900000095367432 MEDIUM

Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory.

EPSS 0.12% · 30.7th percentile

Risk Scores

CVSS v2.0
6.900000095367432
EPSS Score
0.12%
30.7th percentile

Affected Products

VendorProductVersions
pythonpython0, 3.1.0
n/an/an/a
canonicalubuntu_linux11.04, 11.10, 8.04
fedoraprojectfedora13

Timeline

References

…and 5 more

Open in Interactive Console →