CVE-2008-5987: Medium severity Gnome EOG vulnerability
Untrusted search path vulnerability in eog's Python module allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to an erroneous setting of sys.path by the PySysSetArgv function.
References: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504352#4
Test case and more details about this issue (reason's why it can't be fixed in Python) are at: http://www.nabble.com/Bug-484305%3A-bicyclerepair%3A-bike.vim-imports-untrusted-python-files-from-cwd-td18848099.html
Debian patch: http://bugs.debian.org/cgi-bin/bugreport.cgi?msg=5;filename=02sanitizesys.path.patch;att=1;bug=504352
Other sources
Untrusted search path vulnerability in the Python interface in Eye of GNOME (eog) 2.22.3, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySysSetArgv function (CVE-2008-5983).
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Eye of GNOME (eog)to a version that resolves this vulnerability.Patch 02_sanitize_sys.path.patch
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5987?
CVE-2008-5987 is considered a high severity vulnerability due to its potential to allow arbitrary code execution by local users.
How do I fix CVE-2008-5987?
To fix CVE-2008-5987, you should upgrade Eye of GNOME (eog) to a version beyond 2.22.3 that addresses this vulnerability.
Who is affected by CVE-2008-5987?
CVE-2008-5987 affects local users running Eye of GNOME (eog) version 2.22.3 and possibly earlier versions.
What are the potential risks of CVE-2008-5987?
The risks associated with CVE-2008-5987 include the possibility of local users executing malicious code, which can lead to unauthorized access or data compromise.
Is CVE-2008-5987 specific to any operating system?
CVE-2008-5987 is specific to systems running Eye of GNOME (eog), which is commonly found in Linux environments.