PT-2002-1005 · Python+1 · Python+2
Published
2002-10-04
·
Updated
2023-08-02
·
CVE-2002-1119
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Python versions prior to 2.2.1
idle package in Debian GNU/Linux (affected versions not specified)
Description
The issue concerns a predictable temporary file name generation in the
os. execvpe function from os.py in Python, potentially allowing local users to execute arbitrary code via a symlink attack. Additionally, multiple vulnerabilities in the idle package of Debian GNU/Linux may lead to breaches in confidentiality, integrity, and availability of protected information.Recommendations
For Python versions prior to 2.2.1: Update to a version later than 2.2.1 to resolve the issue.
For idle package in Debian GNU/Linux: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Python
Idle