CVE-2008-5985
Untrusted search path vulnerability in the Python interface in Epiphany 2.22.3, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the…
Does this matter?
Lower severity and a low EPSS score (0.37%). Track it; it rarely justifies an emergency change on its own.
Description
Untrusted search path vulnerability in the Python interface in Epiphany 2.22.3, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.37% probability · 31th percentile
- CISA KEV
- Not listed
- Affected
- gnome/epiphany
- Source
- cve@mitre.org
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504363
- http://secunia.com/advisories/34187
- http://www.gentoo.org/security/en/glsa/glsa-200903-16.xml
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:048
- http://www.openwall.com/lists/oss-security/2009/01/26/2
- http://www.securityfocus.com/bid/33441
- https://bugzilla.redhat.com/show_bug.cgi?id=481548
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504363
- http://secunia.com/advisories/34187
- http://www.gentoo.org/security/en/glsa/glsa-200903-16.xml
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:048
- http://www.openwall.com/lists/oss-security/2009/01/26/2
- http://www.securityfocus.com/bid/33441
- https://bugzilla.redhat.com/show_bug.cgi?id=481548
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.