CVE Vulnerabilities

CVE-2008-5984

Published: Jan 28, 2009 | Modified: Aug 08, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW

Untrusted search path vulnerability in the Python plugin in Dia 0.96.1, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).

Affected Software

Name Vendor Start Version End Version
Dia Dia 0.96.1 (including) 0.96.1 (including)
Dia Ubuntu dapper *
Dia Ubuntu gutsy *
Dia Ubuntu hardy *
Dia Ubuntu intrepid *
Dia Ubuntu upstream *

References