Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Gentoo Linux Security Advisory GLSA 200505-14
https://security.gentoo.org/
Severity: Normal
Title: Cheetah: Untrusted module search path
Date: May 19, 2005
Bugs: #92926
ID: 200505-14
Synopsis
=======
Cheetah contains a vulnerability in the module importing code that can
allow a local user to gain escalated privileges.
Background
=========
Cheetah is a Python powered template engine and code generator.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 dev-python/cheetah < 0.9.17-rc1 >= 0.9.17-rc1
==========
Brian Bird discovered that Cheetah searches for modules in the
world-writable /tmp directory.
Impact
=====
A malicious local user could place a module containing a...
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.