After an evaluation, GNOME has moved from Bugzilla to GitLab. Learn more about GitLab.
No new issues can be reported in GNOME Bugzilla anymore.
To report an issue in a GNOME project, go to GNOME GitLab.
Do not go to GNOME Gitlab for: Bluefish, Doxygen, GnuCash, GStreamer, java-gnome, LDTP, NetworkManager, Tomboy.
Bug 569230 - untrusted python modules search path
untrusted python modules search path
Status: RESOLVED OBSOLETE
Product: epiphany
Classification: Core
Component: [obsolete] Bindings:Python
unspecified
Other Linux
: Normal major
: ---
Assigned To: Epiphany Maintainers
Epiphany Maintainers
Depends on:
Blocks: 569273
 
 
Reported: 2009-01-26 18:27 UTC by Bastien Nocera
Modified: 2010-01-23 19:13 UTC
See Also:
GNOME target: ---
GNOME version: ---



Description Bastien Nocera 2009-01-26 18:27:07 UTC
+++ This bug was initially created as a clone of Bug #569214 +++

(From Jan Lieskovsky, https://bugzilla.redhat.com/show_bug.cgi?id=481556)

"Untrusted search path vulnerability in gedit's Python module allows local
users to execute arbitrary code via a Trojan horse Python file in the
current working directory, related to an erroneous setting of sys.path
by the PySys_SetArgv function.

References:
http://www.nabble.com/Bug-484305%3A-bicyclerepair%3A-bike.vim-imports-untrusted-python-files-from-cwd-td18848099.html

Debian bug report for similar eog issue:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504352#4

Proposed patch:
Not sure, if gedi'ts upstream has been reported about this issue.
The Debian patch for similar eog's Python related issue,
available at:

http://bugs.debian.org/cgi-bin/bugreport.cgi?msg=5;filename=02_sanitize_sys.path.patch;att=1;bug=504352

should be sufficient to resolve this issue."

There's no CVE assigned yet, but one has been requested.  The security severity is considered "low".
Comment 1 Christian Persch 2009-01-26 18:58:10 UTC
(Just btw, iirc this code was adapted from nautilus's python extension support, so it's possible the same bug applies to nautilus too.)
Comment 2 Christian Persch 2009-04-10 18:23:06 UTC
Reality check.
Comment 3 Diego Escalante Urrelo (not reading bugmail) 2010-01-23 19:13:12 UTC
We no longer support Python.