Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24356
HistoryApr 10, 2020 - 12:53 a.m.

Arbitrary Code Execution

2020-04-1000:53:08
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

0.001 Low

EPSS

Percentile

23.7%

python is vulnerable to arbitrary code execution. It was found that many applications embedding the Python interpreter did not specify a valid full path to the script or application when calling the PySys_SetArgv API function, which could result in the addition of the current working directory to the module search path (sys.path). A local attacker able to trick a victim into running such an application in an attacker-controlled directory could use this flaw to execute code with the victim’s privileges. This update adds the PySys_SetArgvEx API. Developers can modify their applications to use this new API, which sets sys.argv without modifying sys.path.

References