Csound 'PySys_SetArgv' Remote Command Execution Vulnerability
BID:33446
Info
Csound 'PySys_SetArgv' Remote Command Execution Vulnerability
| Bugtraq ID: | 33446 |
| Class: | Design Error |
| CVE: |
CVE-2008-5986 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 26 2009 12:00AM |
| Updated: | Apr 13 2015 08:26PM |
| Credit: | James Vega |
| Vulnerable: |
Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Cesare Marilungo Csound 5.09 Cesare Marilungo Csound 5.08 |
| Not Vulnerable: | |
Discussion
Csound 'PySys_SetArgv' Remote Command Execution Vulnerability
Csound is prone to a remote command-execution vulnerability.
An attacker could exploit this issue by enticing an unsuspecting victim to execute the vulnerable application in a directory containing a malicious Python file. A successful exploit will allow arbitrary Python commands to run with the privileges of the currently logged-in user.
Csound is prone to a remote command-execution vulnerability.
An attacker could exploit this issue by enticing an unsuspecting victim to execute the vulnerable application in a directory containing a malicious Python file. A successful exploit will allow arbitrary Python commands to run with the privileges of the currently logged-in user.
Exploit / POC
Csound 'PySys_SetArgv' Remote Command Execution Vulnerability
An attacker may exploit this issue using commonly available tools.
An attacker may exploit this issue using commonly available tools.
Solution / Fix
Csound 'PySys_SetArgv' Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Csound 'PySys_SetArgv' Remote Command Execution Vulnerability
References:
References:
- csound: Python scripts load modules from current directory (James Vega)
- csound: untrusted python modules search path (Csound)
- Csounds Homepage (Cesare Marilungo)