CVE-2008-5984
Untrusted search path vulnerability in the Python plugin in Dia 0.96.1, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the…
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
Untrusted search path vulnerability in the Python plugin in Dia 0.96.1, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.40% probability · 33th percentile
- CISA KEV
- Not listed
- Affected
- dia/dia
- Source
- cve@mitre.org
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504251
- http://secunia.com/advisories/33672
- http://secunia.com/advisories/33703
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:040
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:046
- http://www.openwall.com/lists/oss-security/2009/01/26/2
- http://www.securityfocus.com/bid/33448
- https://bugzilla.redhat.com/show_bug.cgi?id=481551
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48262
- https://www.redhat.com/archives/fedora-package-announce/2009-January/msg01065.html
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504251
- http://secunia.com/advisories/33672
- http://secunia.com/advisories/33703
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:040
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:046
- http://www.openwall.com/lists/oss-security/2009/01/26/2
- http://www.securityfocus.com/bid/33448
- https://bugzilla.redhat.com/show_bug.cgi?id=481551
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48262
- https://www.redhat.com/archives/fedora-package-announce/2009-January/msg01065.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.