CVE-2009-0367

N/A Unknown
Published: March 05, 2009 Modified: April 23, 2026
View on NVD

Description

The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by using a whitelisted module that imports an unsafe module, then using a hierarchical module name to access the unsafe module through the whitelisted module.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/34058
Source: cve@mitre.org
Vendor Advisory
http://www.vupen.com/english/advisories/2009/0595
Source: cve@mitre.org
Patch Vendor Advisory
http://www.wesnoth.org/forum/viewtopic.php?t=24247
Source: cve@mitre.org
Patch Vendor Advisory
http://www.wesnoth.org/forum/viewtopic.php?t=24340
Source: cve@mitre.org
Patch Vendor Advisory
http://launchpad.net/bugs/335089
Source: af854a3a-2127-422b-91ae-364da2661108
http://launchpad.net/bugs/336396
Source: af854a3a-2127-422b-91ae-364da2661108
http://launchpad.net/bugs/cve/2009-0367
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/34058
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/34236
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2009/dsa-1737
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2009/0595
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
http://www.wesnoth.org/forum/viewtopic.php?t=24247
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
http://www.wesnoth.org/forum/viewtopic.php?t=24340
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/49058
Source: af854a3a-2127-422b-91ae-364da2661108
https://gna.org/bugs/index.php?13048
Source: af854a3a-2127-422b-91ae-364da2661108

26 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
7.3%
92th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

wesnoth