Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux

CVE-2009-0367
CVE information
Published
Last Modified
CVSSv2.0 Severity
Impact Analysis
Description
The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by using a whitelisted module that imports an unsafe module, then using a hierarchical module name to access the unsafe module through the whitelisted module..
CVSSv2.0 Score
- Severity
- High
- Base Score
- 9.3/10
- Exploit Score
- 8.6/10
- Access Vector
- Network
- Access Complexity
- Medium
- Authentication Required
- None
- Impact Score
- 10/10
- Confidentiality Impact
- Complete
- Availability Impact
- Complete
- Integrity Impact
- Complete
Products Affected
CPE | Affected | Vulnerable | Excluding | Edit |
---|---|---|---|---|
cpe:2.3:a:wesnoth:wesnoth:1.5.6:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:wesnoth:wesnoth:1.4.6:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:wesnoth:wesnoth:1.5.4:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:wesnoth:wesnoth:1.5.10:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:wesnoth:wesnoth:1.4.5:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:wesnoth:wesnoth:1.5.3:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:wesnoth:wesnoth:1.4.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:wesnoth:wesnoth:1.5.7:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:wesnoth:wesnoth:1.5.8:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:wesnoth:wesnoth:1.5.9:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:wesnoth:wesnoth:1.5.0:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:wesnoth:wesnoth:1.5.5:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:wesnoth:wesnoth:1.4:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:wesnoth:wesnoth:1.5.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:wesnoth:wesnoth:1.4.3:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:wesnoth:wesnoth:1.4.2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:wesnoth:wesnoth:1.4.4:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:wesnoth:wesnoth:1.4.7:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:wesnoth:wesnoth:1.5.2:*:*:*:*:*:*:* |
Yes
|
- | - |
References
- http://www.wesnoth.org/forum/viewtopic.php?t=24340
- http://secunia.com/advisories/34058
- http://www.wesnoth.org/forum/viewtopic.php?t=24247
- https://gna.org/bugs/index.php?13048
- http://www.vupen.com/english/advisories/2009/0595
- http://launchpad.net/bugs/336396
- http://launchpad.net/bugs/335089
- http://www.debian.org/security/2009/dsa-1737
- http://packages.debian.org/changelogs/pool/main/w/wesnoth/wesnoth_1.5.12-1/changelog
- http://packages.debian.org/changelogs/pool/main/w/wesnoth/wesnoth_1.4.7-4/changelog
- http://launchpad.net/bugs/cve/2009-0367
- http://secunia.com/advisories/34236
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49058