CVE-2002-1119

os._execvpe from os.py in Python 2.2.1 and earlier creates temporary files with predictable names, which could allow local users to execute arbitrary code via a symlink attack.
References
Link Resource
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-045.0.txt Broken Link Third Party Advisory
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000527 Third Party Advisory
http://mail.python.org/pipermail/python-dev/2002-August/027229.html Mailing List Vendor Advisory
http://marc.info/?l=bugtraq&m=104333092200589&w=2 Mailing List
http://www.debian.org/security/2002/dsa-159 Patch Vendor Advisory
http://www.iss.net/security_center/static/10009.php Vendor Advisory
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-082.php Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2002-202.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2003-048.html Third Party Advisory
http://www.securityfocus.com/bid/5581 Patch Third Party Advisory VDB Entry Vendor Advisory
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-045.0.txt Broken Link Third Party Advisory
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000527 Third Party Advisory
http://mail.python.org/pipermail/python-dev/2002-August/027229.html Mailing List Vendor Advisory
http://marc.info/?l=bugtraq&m=104333092200589&w=2 Mailing List
http://www.debian.org/security/2002/dsa-159 Patch Vendor Advisory
http://www.iss.net/security_center/static/10009.php Vendor Advisory
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-082.php Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2002-202.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2003-048.html Third Party Advisory
http://www.securityfocus.com/bid/5581 Patch Third Party Advisory VDB Entry Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:python:python:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:40

Type Values Removed Values Added
References () ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-045.0.txt - Broken Link, Third Party Advisory () ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-045.0.txt - Broken Link, Third Party Advisory
References () http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000527 - Third Party Advisory () http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000527 - Third Party Advisory
References () http://mail.python.org/pipermail/python-dev/2002-August/027229.html - Mailing List, Vendor Advisory () http://mail.python.org/pipermail/python-dev/2002-August/027229.html - Mailing List, Vendor Advisory
References () http://marc.info/?l=bugtraq&m=104333092200589&w=2 - Mailing List () http://marc.info/?l=bugtraq&m=104333092200589&w=2 - Mailing List
References () http://www.debian.org/security/2002/dsa-159 - Patch, Vendor Advisory () http://www.debian.org/security/2002/dsa-159 - Patch, Vendor Advisory
References () http://www.iss.net/security_center/static/10009.php - Vendor Advisory () http://www.iss.net/security_center/static/10009.php - Vendor Advisory
References () http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-082.php - Third Party Advisory () http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-082.php - Third Party Advisory
References () http://www.redhat.com/support/errata/RHSA-2002-202.html - Third Party Advisory () http://www.redhat.com/support/errata/RHSA-2002-202.html - Third Party Advisory
References () http://www.redhat.com/support/errata/RHSA-2003-048.html - Third Party Advisory () http://www.redhat.com/support/errata/RHSA-2003-048.html - Third Party Advisory
References () http://www.securityfocus.com/bid/5581 - Patch, Third Party Advisory, VDB Entry, Vendor Advisory () http://www.securityfocus.com/bid/5581 - Patch, Third Party Advisory, VDB Entry, Vendor Advisory

02 Aug 2023, 18:00

Type Values Removed Values Added
First Time Python
Python python
References (BID) http://www.securityfocus.com/bid/5581 - Patch, Vendor Advisory (BID) http://www.securityfocus.com/bid/5581 - Patch, Third Party Advisory, VDB Entry, Vendor Advisory
References (CONECTIVA) http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000527 - (CONECTIVA) http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000527 - Third Party Advisory
References (MANDRAKE) http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-082.php - (MANDRAKE) http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-082.php - Third Party Advisory
References (CALDERA) ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-045.0.txt - (CALDERA) ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-045.0.txt - Broken Link, Third Party Advisory
References (MISC) http://mail.python.org/pipermail/python-dev/2002-August/027229.html - (MISC) http://mail.python.org/pipermail/python-dev/2002-August/027229.html - Mailing List, Vendor Advisory
References (BUGTRAQ) http://marc.info/?l=bugtraq&m=104333092200589&w=2 - (BUGTRAQ) http://marc.info/?l=bugtraq&m=104333092200589&w=2 - Mailing List
References (REDHAT) http://www.redhat.com/support/errata/RHSA-2002-202.html - (REDHAT) http://www.redhat.com/support/errata/RHSA-2002-202.html - Third Party Advisory
References (REDHAT) http://www.redhat.com/support/errata/RHSA-2003-048.html - (REDHAT) http://www.redhat.com/support/errata/RHSA-2003-048.html - Third Party Advisory
CPE cpe:2.3:a:python_software_foundation:python:*:*:*:*:*:*:*:* cpe:2.3:a:python:python:*:*:*:*:*:*:*:*

Information

Published : 2002-10-04 04:00

Updated : 2024-11-20 23:40


NVD link : CVE-2002-1119

Mitre link : CVE-2002-1119

CVE.ORG link : CVE-2002-1119


JSON object : View

Products Affected

python

  • python