CVE-2009-0367: Critical severity Wesnoth Wesnoth vulnerability
Published Mar 5, 2009
·Updated
The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by using a whitelisted module that imports an unsafe module, then using a hierarchical module name to access the unsafe module through the whitelisted module.
Affected Software
19 affected components
Wesnoth Wesnoth=1.4
Wesnoth Wesnoth=1.4.1
Wesnoth Wesnoth=1.4.2
Wesnoth Wesnoth=1.4.3
Wesnoth Wesnoth=1.4.4
Wesnoth Wesnoth=1.4.5
Wesnoth Wesnoth=1.4.6
Wesnoth Wesnoth=1.4.7
Wesnoth Wesnoth=1.5.0
Wesnoth Wesnoth=1.5.1
Wesnoth Wesnoth=1.5.2
Wesnoth Wesnoth=1.5.3
Wesnoth Wesnoth=1.5.4
Wesnoth Wesnoth=1.5.5
Wesnoth Wesnoth=1.5.6
Wesnoth Wesnoth=1.5.7
Wesnoth Wesnoth=1.5.8
Wesnoth Wesnoth=1.5.9
Wesnoth Wesnoth=1.5.10
Remediation
Patch Available
Patch Available
Patch Available
Event History
Mar 5, 2009
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·02:30 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0367?
CVE-2009-0367 has a severity rating of high due to the potential for remote code execution.
2
How do I fix CVE-2009-0367?
To fix CVE-2009-0367, upgrade to Wesnoth version 1.5.11 or later.
3
What software is affected by CVE-2009-0367?
CVE-2009-0367 affects Wesnoth versions 1.4.x and 1.5.x up to 1.5.10.
4
Can CVE-2009-0367 be exploited remotely?
Yes, CVE-2009-0367 can be exploited remotely, allowing attackers to execute arbitrary code.
5
What type of vulnerability is CVE-2009-0367?
CVE-2009-0367 is a code execution vulnerability that occurs due to improper sandboxing in the Python AI module.