Security Advisory

CVE-2008-5986

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2009-01-28 11:00:00
Last updated 2024-08-07 11:13:13
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Untrusted search path vulnerability in the (1) "VST plugin with Python scripting" and (2) "VST plugin for writing score generators in Python" in Csound 5.08.2, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).