CVE-2002-1119

os._execvpe from os.py in Python 2.2.1 and earlier creates temporary files with predictable names, which could allow local users to execute arbitrary code via a symlink attack.
Configurations

Configuration 1 (hide)

cpe:2.3:a:python:python:*:*:*:*:*:*:*:*

History

02 Aug 2023, 18:00

Type Values Removed Values Added
CPE cpe:2.3:a:python_software_foundation:python:*:*:*:*:*:*:*:* cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
First Time Python
Python python
References (CALDERA) ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-045.0.txt - (CALDERA) ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-045.0.txt - Broken Link, Third Party Advisory
References (BID) http://www.securityfocus.com/bid/5581 - Patch, Vendor Advisory (BID) http://www.securityfocus.com/bid/5581 - Patch, Third Party Advisory, VDB Entry, Vendor Advisory
References (REDHAT) http://www.redhat.com/support/errata/RHSA-2002-202.html - (REDHAT) http://www.redhat.com/support/errata/RHSA-2002-202.html - Third Party Advisory
References (MANDRAKE) http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-082.php - (MANDRAKE) http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-082.php - Third Party Advisory
References (CONECTIVA) http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000527 - (CONECTIVA) http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000527 - Third Party Advisory
References (BUGTRAQ) http://marc.info/?l=bugtraq&m=104333092200589&w=2 - (BUGTRAQ) http://marc.info/?l=bugtraq&m=104333092200589&w=2 - Mailing List
References (MISC) http://mail.python.org/pipermail/python-dev/2002-August/027229.html - (MISC) http://mail.python.org/pipermail/python-dev/2002-August/027229.html - Mailing List, Vendor Advisory
References (REDHAT) http://www.redhat.com/support/errata/RHSA-2003-048.html - (REDHAT) http://www.redhat.com/support/errata/RHSA-2003-048.html - Third Party Advisory

Information

Published : 2002-10-04 04:00

Updated : 2023-12-10 10:17


NVD link : CVE-2002-1119

Mitre link : CVE-2002-1119

CVE.ORG link : CVE-2002-1119


JSON object : View

Products Affected

python

  • python