Back to search
CVE-2009-0367
Published: Mar 5, 2009
Modified: Aug 7, 2024
PUBLISHED
Description
The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by using a whitelisted module that imports an unsafe module, then using a hierarchical module name to access the unsafe module through the whitelisted module.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://launchpad.net/bugs/336396
x_refsource_CONFIRM
https://gna.org/bugs/index.php?13048
x_refsource_CONFIRM
wesnoth-pythonai-code-execution(49058)
vdb-entry
x_refsource_XF
http://www.wesnoth.org/forum/viewtopic.php?t=24340
x_refsource_CONFIRM
http://www.wesnoth.org/forum/viewtopic.php?t=24247
x_refsource_CONFIRM
34058
third-party-advisory
x_refsource_SECUNIA
ADV-2009-0595
vdb-entry
x_refsource_VUPEN
http://launchpad.net/bugs/cve/2009-0367
x_refsource_CONFIRM
34236
third-party-advisory
x_refsource_SECUNIA
DSA-1737
vendor-advisory
x_refsource_DEBIAN
http://launchpad.net/bugs/335089
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now