PT-2002-1005 · Python+1 · Python+2

Publicado

2002-10-04

·

Atualizado

2023-08-02

·

CVE-2002-1119

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Python versions prior to 2.2.1 idle package in Debian GNU/Linux (affected versions not specified)
Description The issue concerns a predictable temporary file name generation in the os. execvpe function from os.py in Python, potentially allowing local users to execute arbitrary code via a symlink attack. Additionally, multiple vulnerabilities in the idle package of Debian GNU/Linux may lead to breaches in confidentiality, integrity, and availability of protected information.
Recommendations For Python versions prior to 2.2.1: Update to a version later than 2.2.1 to resolve the issue. For idle package in Debian GNU/Linux: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-01348
CVE-2002-1119
DSA-159

Produtos afetados

Debian
Python
Idle