Name | CVE-2002-1119 |
Description | os._execvpe from os.py in Python 2.2.1 and earlier creates temporary files with predictable names, which could allow local users to execute arbitrary code via a symlink attack. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-159 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
python1.5 | source | woody | 1.5.2-23.1 | DSA-159 | ||
python1.5 | source | (unstable) | 1.5.2-24 | |||
python2.1 | source | woody | 2.1.3-3.1 | DSA-159 | ||
python2.1 | source | (unstable) | 2.1.3-6a | |||
python2.2 | source | woody | 2.2.1-4.1 | DSA-159 | ||
python2.2 | source | (unstable) | 2.2.1-8 | |||
python2.3 | source | (unstable) | (not affected) |