CVE Vulnerabilities

CVE-2009-3894

Published: Nov 29, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
6.2 MODERATE
AV:L/AC:H/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple untrusted search path vulnerabilities in dstat before 0.7.0 allow local users to gain privileges via a Trojan horse Python module in (1) the current working directory or (2) a certain subdirectory of the current working directory.

Affected Software

NameVendorStart VersionEnd Version
DstatDag.wieers*0.6.9 (including)
DstatDag.wieers0.1 (including)0.1 (including)
DstatDag.wieers0.2 (including)0.2 (including)
DstatDag.wieers0.3 (including)0.3 (including)
DstatDag.wieers0.4 (including)0.4 (including)
DstatDag.wieers0.5 (including)0.5 (including)
DstatDag.wieers0.5.2 (including)0.5.2 (including)
DstatDag.wieers0.5.3 (including)0.5.3 (including)
DstatDag.wieers0.5.4 (including)0.5.4 (including)
DstatDag.wieers0.5.5 (including)0.5.5 (including)
DstatDag.wieers0.5.6 (including)0.5.6 (including)
DstatDag.wieers0.5.7 (including)0.5.7 (including)
DstatDag.wieers0.5.8 (including)0.5.8 (including)
DstatDag.wieers0.5.9 (including)0.5.9 (including)
DstatDag.wieers0.5.10 (including)0.5.10 (including)
DstatDag.wieers0.6.0 (including)0.6.0 (including)
DstatDag.wieers0.6.1 (including)0.6.1 (including)
DstatDag.wieers0.6.2 (including)0.6.2 (including)
DstatDag.wieers0.6.3 (including)0.6.3 (including)
DstatDag.wieers0.6.4 (including)0.6.4 (including)
DstatDag.wieers0.6.5 (including)0.6.5 (including)
DstatDag.wieers0.6.6 (including)0.6.6 (including)
DstatDag.wieers0.6.7 (including)0.6.7 (including)
DstatDag.wieers0.6.8 (including)0.6.8 (including)
Red Hat Enterprise Linux 5RedHatdstat-0:0.6.6-3.el5_4.1*
DstatUbuntudapper*
DstatUbuntuhardy*
DstatUbuntuintrepid*
DstatUbuntujaunty*
DstatUbuntukarmic*
DstatUbuntuupstream*

References