GLSA-201009-08 : python-updater: Untrusted search path

high Nessus Plugin ID 49637

Language:

Synopsis

The remote Gentoo host is missing one or more security-related patches.

Description

The remote host is affected by the vulnerability described in GLSA-201009-08 (python-updater: Untrusted search path)

Robert Buchholz of the Gentoo Security Team reported that python-updater includes the current working directory and subdirectories in the Python module search path (sys.path) before calling 'import'.
Impact :

A local attacker could entice the root user to run 'python-updater' from a directory containing a specially crafted Python module, resulting in the execution of arbitrary code with root privileges.
Workaround :

Do not run 'python-updater' from untrusted working directories.

Solution

All python-updater users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose '>=app-admin/python-updater-0.7-r1'

See Also

https://security.gentoo.org/glsa/201009-08

Plugin Details

Severity: High

ID: 49637

File Name: gentoo_GLSA-201009-08.nasl

Version: 1.9

Type: local

Published: 9/22/2010

Updated: 1/6/2021

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:gentoo:linux:python-updater, cpe:/o:gentoo:linux

Required KB Items: Host/local_checks_enabled, Host/Gentoo/release, Host/Gentoo/qpkg-list

Patch Publication Date: 9/21/2010

Reference Information

GLSA: 201009-08