eog 'PySys_SetArgv' Remote Command Execution Vulnerability
BID:33443
Info
eog 'PySys_SetArgv' Remote Command Execution Vulnerability
| Bugtraq ID: | 33443 |
| Class: | Design Error |
| CVE: |
CVE-2008-5987 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 26 2009 12:00AM |
| Updated: | May 07 2015 05:06PM |
| Credit: | Jan Lieskovsky |
| Vulnerable: |
Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 GNOME eog 2.22.3 GNOME eog 2.20.4 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
eog 'PySys_SetArgv' Remote Command Execution Vulnerability
The 'eog' (Eye of GNOME) program is prone to a remote command-execution vulnerability.
An attacker could exploit this issue by enticing an unsuspecting victim to execute the vulnerable application in a directory containing a malicious Python file. A successful exploit will allow arbitrary Python commands to run with the privileges of the currently logged-in user.
The 'eog' (Eye of GNOME) program is prone to a remote command-execution vulnerability.
An attacker could exploit this issue by enticing an unsuspecting victim to execute the vulnerable application in a directory containing a malicious Python file. A successful exploit will allow arbitrary Python commands to run with the privileges of the currently logged-in user.
Exploit / POC
eog 'PySys_SetArgv' Remote Command Execution Vulnerability
An attacker may exploit this issue using commonly available tools.
An attacker may exploit this issue using commonly available tools.
Solution / Fix
eog 'PySys_SetArgv' Remote Command Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2008.1 x86_64
Mandriva Linux Mandrake 2008.1
Mandriva Linux Mandrake 2009.0
Mandriva Linux Mandrake 2009.0 x86_64
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2008.1 x86_64
-
Mandriva eog-2.22.0-2.1mdv2008.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva eog-devel-2.22.0-2.1mdv2008.1.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.1
-
Mandriva eog-2.22.0-2.1mdv2008.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva eog-devel-2.22.0-2.1mdv2008.1.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.0
-
Mandriva eog-2.24.0-1.1mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva eog-devel-2.24.0-1.1mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva eog-2.24.0-1.1mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva eog-devel-2.24.0-1.1mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/
References
eog 'PySys_SetArgv' Remote Command Execution Vulnerability
References:
References:
- Bugzilla Bug 481553 eog: untrusted python modules search path (Jan Lieskovsky)
- Debian Bug 504352 eog: Python scripts load modules from current directory (James Vega)
- Eye of GNOME Homepage (GNOME)