Lucene search

K
cvelistMitreCVELIST:CVE-2008-5983
HistoryJan 28, 2009 - 2:00 a.m.

CVE-2008-5983

2009-01-2802:00:00
mitre
www.cve.org
2

6.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

23.7%

Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory.

References