CVE-2009-0367
Last modified
CVE-2009-0367 is a vulnerability of currently unknown severity. The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by using a whitelisted module that imports an unsafe module, then using a hierarchical module name to access the unsafe module through the whitelisted module.. EPSS estimates a 10.94% chance of exploitation in the next 30 days.
Description
The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by using a whitelisted module that imports an unsafe module, then using a hierarchical module name to access the unsafe module through the whitelisted module.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wesnoth | Wesnoth | 1.4 |
| Wesnoth | Wesnoth | 1.4.1 |
| Wesnoth | Wesnoth | 1.4.2 |
| Wesnoth | Wesnoth | 1.4.3 |
| Wesnoth | Wesnoth | 1.4.4 |
| Wesnoth | Wesnoth | 1.4.5 |
| Wesnoth | Wesnoth | 1.4.6 |
| Wesnoth | Wesnoth | 1.4.7 |
| Wesnoth | Wesnoth | 1.5.0 |
| Wesnoth | Wesnoth | 1.5.1 |
| Wesnoth | Wesnoth | 1.5.2 |
| Wesnoth | Wesnoth | 1.5.3 |
| Wesnoth | Wesnoth | 1.5.4 |
| Wesnoth | Wesnoth | 1.5.5 |
| Wesnoth | Wesnoth | 1.5.6 |
| Wesnoth | Wesnoth | 1.5.7 |
| Wesnoth | Wesnoth | 1.5.8 |
| Wesnoth | Wesnoth | 1.5.9 |
| Wesnoth | Wesnoth | 1.5.10 |
References
- http://secunia.com/advisories/34058Vendor Advisory
- http://www.vupen.com/english/advisories/2009/0595Patch, Vendor Advisory
- http://www.wesnoth.org/forum/viewtopic.php?t=24247Patch, Vendor Advisory
- http://www.wesnoth.org/forum/viewtopic.php?t=24340Patch, Vendor Advisory
- http://secunia.com/advisories/34058Vendor Advisory
- http://www.vupen.com/english/advisories/2009/0595Patch, Vendor Advisory
- http://www.wesnoth.org/forum/viewtopic.php?t=24247Patch, Vendor Advisory
- http://www.wesnoth.org/forum/viewtopic.php?t=24340Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0367?
How severe is CVE-2009-0367?
How do I fix CVE-2009-0367?
Are you affected by CVE-2009-0367?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
