PT-2002-1005 · Python+1 · Python+2

Published

2002-10-04

·

Updated

2023-08-02

·

CVE-2002-1119

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Python versions prior to 2.2.1 idle package in Debian GNU/Linux (affected versions not specified)
Description The issue concerns a predictable temporary file name generation in the os. execvpe function from os.py in Python, potentially allowing local users to execute arbitrary code via a symlink attack. Additionally, multiple vulnerabilities in the idle package of Debian GNU/Linux may lead to breaches in confidentiality, integrity, and availability of protected information.
Recommendations For Python versions prior to 2.2.1: Update to a version later than 2.2.1 to resolve the issue. For idle package in Debian GNU/Linux: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-01348
CVE-2002-1119
DSA-159

Affected Products

Debian
Python
Idle