Lucene search

K
prionPRIOn knowledge basePRION:CVE-2008-5983
HistoryJan 28, 2009 - 2:30 a.m.

Design/Logic Flaw

2009-01-2802:30:00
PRIOn knowledge base
www.prio-n.com
6

7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

23.7%

Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory.

References