Untrusted search path vulnerability in Catfish 0.6.0 through 1.0.0, when a Fedora package such as 0.8.2-1 is not used, allows local users to gain privileges via a Trojan horse bin/catfish.pyc under the current working directory.
Advisories
Source ID Title
EUVD EUVD EUVD-2014-2135 Untrusted search path vulnerability in Catfish 0.6.0 through 1.0.0, when a Fedora package such as 0.8.2-1 is not used, allows local users to gain privileges via a Trojan horse bin/catfish.pyc under the current working directory.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T10:05:57.906Z

Reserved: 2014-02-24T00:00:00

Link: CVE-2014-2095

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2014-02-26T14:55:08.583

Modified: 2025-04-12T10:46:40.837

Link: CVE-2014-2095

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses