« List of all CVEs

CVE-2015-5652

Published: 10/5/2015 Last updated: 8/6/2024 Reserved: 7/24/2015

Untrusted search path vulnerability in python.exe in Python through 3.5.0 on Windows allows local users to gain privileges via a Trojan horse readline.pyd file in the current working directory. NOTE: the vendor says "It was determined that this is a longtime behavior of Python that cannot really be altered at this point."

CNA assigner: jpcert (ede6fdc4-6654-4307-a26d-3331c018e2ce) Requested by: n/a

Opam packages affected (7)

conf-python-2-7 conf-python-2-7-dev conf-python-3 conf-python-3-7 conf-python-3-dev py termbox

Products affected (1)

Product Vendor Version
n/a n/a < 6.12

References (20)