Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 257011 (CVE-2009-0317) - nautilus-python Untrusted search path vulnerability (CVE-2009-0317)
Summary: nautilus-python Untrusted search path vulnerability (CVE-2009-0317)
Status: RESOLVED FIXED
Alias: CVE-2009-0317
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Christian Faulhammer (RETIRED)
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard:
Keywords:
Depends on: CVE-2008-5983
Blocks: 78021
  Show dependency tree
 
Reported: 2009-01-30 22:55 UTC by Stefan Behte (RETIRED)
Modified: 2009-02-25 16:35 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2009-01-30 22:55:16 UTC
CVE-2009-0317 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0317):
  Untrusted search path vulnerability in the Python language bindings
  for Nautilus (nautilus-python) allows local users to execute
  arbitrary code via a Trojan horse Python file in the current working
  directory, related to a vulnerability in the PySys_SetArgv function
  (CVE-2008-5983).
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2009-01-30 23:40:57 UTC
I am not sure whether this bug is being tracked upstream. Please see the blocker for details and a patch example.
Comment 2 Gilles Dartiguelongue (RETIRED) gentoo-dev 2009-02-23 21:11:35 UTC
hum actually we don't ship nautilus-python. It is a separate package from nautilus and is tracked at bug #78021
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2009-02-24 11:45:24 UTC
Fauli, I'll reassign this bug to you as you seem to sponsor inclusion of nautilus-python in the tree. Security is not tracking bugs for ebuilds in overlays, but you need to make sure this bug is fixed before tree inclusion. Thanks!

Gnome, I'm keeping you in cc, feel free to remove yourself.
Comment 4 Christian Faulhammer (RETIRED) gentoo-dev 2009-02-24 16:30:52 UTC
https://bugzilla.redhat.com/show_bug.cgi?id=481570 suggests http://bugs.debian.org/cgi-bin/bugreport.cgi?msg=5;filename=pythonpath.diff;att=1;bug=504251 as fix, which is for dia, so I have to investigate.  Thanks for your notice.
Comment 5 Robert Buchholz (RETIRED) gentoo-dev 2009-02-24 20:16:13 UTC
Well, the fix is "along those lines", but the patch won't directly apply.
Comment 6 Christian Faulhammer (RETIRED) gentoo-dev 2009-02-25 16:35:16 UTC
A fix is in the overlay, provided by Mark Lee (the official overlay maintainer) and is pushed upstream.