CVE-2015-5652: High severity python 2.7 vulnerability
Published Oct 5, 2015
·Updated
Untrusted search path vulnerability in python.exe in Python through 3.5.0 on Windows allows local users to gain privileges via a Trojan horse readline.pyd file in the current working directory. NOTE: the vendor says "It was determined that this is a longtime behavior of Python that cannot really be altered at this point."
Affected Software
2 affected components
Python Python<=3.5.0
Microsoft Windows
Event History
Oct 5, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5652?
The severity of CVE-2015-5652 is classified as moderate due to the potential for local privilege escalation.
2
How do I fix CVE-2015-5652?
To fix CVE-2015-5652, ensure that Python is upgraded to a version higher than 3.5.0.
3
Who is affected by CVE-2015-5652?
Users of Python through version 3.5.0 on Windows systems are affected by CVE-2015-5652.
4
What type of vulnerability is CVE-2015-5652?
CVE-2015-5652 is an untrusted search path vulnerability.
5
Can CVE-2015-5652 be exploited remotely?
CVE-2015-5652 cannot be exploited remotely; it requires local access to execute code.