CVE-2009-0318
published 2009-01-28CVE-2009-0318: Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan horse…
PriorityP419medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.39%
31.2th percentile
Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnumeric | < gnumeric 1.8.4-3 (bookworm) | gnumeric 1.8.4-3 (bookworm) |
| gnome | gnumeric | >= 0 < 1.8.4-3 | 1.8.4-3 |
| gnome | gnumeric | >= 0 < 1.8.4-3 | 1.8.4-3 |
| gnome | gnumeric | >= 0 < 1.8.4-3 | 1.8.4-3 |
| gnome | gnumeric | >= 0 < 1.8.4-3 | 1.8.4-3 |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9LOW
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2009-0318: gnumeric - Untrusted search path vulnerability in the GObject Python interpreter wrapper in...
vendor_debian·2009·CVSS 6.9
CVE-2009-0318 [MEDIUM] CVE-2009-0318: gnumeric - Untrusted search path vulnerability in the GObject Python interpreter wrapper in...
Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).
Scope: local
bookworm: resolved (fixed in 1.8.4-3)
bullseye: resolved (fixed in 1.8.4-3)
forky: resolved (fixed in 1.8.4-3)
sid: resolved (fixed in 1.8.4-3)
trixie: resolved (fixed in 1.8.4-3)
Red Hat
Gnumeric: untrusted python modules search path
vendor_redhat·2008-08-06·CVSS 6.9
CVE-2009-0318 [MEDIUM] Gnumeric: untrusted python modules search path
Gnumeric: untrusted python modules search path
Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).
GHSA
GHSA-9cr7-r39p-2mx5: Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan ho
ghsa_unreviewed·2022-05-02·CVSS 6.9
CVE-2009-0318 [MEDIUM] GHSA-9cr7-r39p-2mx5: Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan ho
Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).
OSV
CVE-2009-0318: Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan ho
osv·2009-01-28·CVSS 6.9
CVE-2009-0318 [MEDIUM] CVE-2009-0318: Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan ho
Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).
No detection rules found.
No public exploits indexed.
http://bugzilla.gnome.org/show_bug.cgi?id=569648http://secunia.com/advisories/33707http://secunia.com/advisories/33823http://security.gentoo.org/glsa/glsa-200904-03.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:043http://www.openwall.com/lists/oss-security/2009/01/26/2http://www.securityfocus.com/bid/33438https://bugzilla.redhat.com/show_bug.cgi?id=481572https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00211.htmlhttp://bugzilla.gnome.org/show_bug.cgi?id=569648http://secunia.com/advisories/33707http://secunia.com/advisories/33823http://security.gentoo.org/glsa/glsa-200904-03.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:043http://www.openwall.com/lists/oss-security/2009/01/26/2http://www.securityfocus.com/bid/33438https://bugzilla.redhat.com/show_bug.cgi?id=481572https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00211.html
2009-01-28
Published