CVE-2008-5987EOG vulnerability

6 documents6 sources
Severity
6.9MEDIUMNVD
EPSS
0.1%
top 81.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 28
Latest updateMay 17

Description

Untrusted search path vulnerability in the Python interface in Eye of GNOME (eog) 2.22.3, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 3.4 | Impact: 10.0

Affected Packages3 packages

Debiangnome/eog< 2.22.3-2+3
NVDgnome/eog2.22.3
debiandebian/eog< eog 2.22.3-2 (bookworm)

🔴Vulnerability Details

2
GHSA
GHSA-5g97-43jg-qgrv: Untrusted search path vulnerability in the Python interface in Eye of GNOME (eog) 22022-05-17
OSV
CVE-2008-5987: Untrusted search path vulnerability in the Python interface in Eye of GNOME (eog) 22009-01-28

📋Vendor Advisories

2
Red Hat
eog: untrusted python modules search path2008-11-02
Debian
CVE-2008-5987: eog - Untrusted search path vulnerability in the Python interface in Eye of GNOME (eog...2008

💬Community

1
Bugzilla
CVE-2008-5987 eog: untrusted python modules search path2009-01-26