« List of all CVEs

CVE-2015-5652

Published: 10/5/2015 Last updated: 8/6/2024 Reserved: 7/24/2015

Untrusted search path vulnerability in python.exe in Python through 3.5.0 on Windows allows local users to gain privileges via a Trojan horse readline.pyd file in the current working directory. NOTE: the vendor says "It was determined that this is a longtime behavior of Python that cannot really be altered at this point."

CNA assigner: jpcert (ede6fdc4-6654-4307-a26d-3331c018e2ce) Requested by: n/a

Opam packages affected (7)

conf-python-2-7 conf-python-2-7-dev conf-python-3 conf-python-3-7 conf-python-3-dev py termbox

Products affected (0)

No product listed.

References (20)