Untrusted search path vulnerability in the Python plugin in Dia 0.96.1, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dia | Dia | 0.96.1 (including) | 0.96.1 (including) |
Dia | Ubuntu | dapper | * |
Dia | Ubuntu | gutsy | * |
Dia | Ubuntu | hardy | * |
Dia | Ubuntu | intrepid | * |
Dia | Ubuntu | upstream | * |