Unrated severityNVD Advisory· Published Nov 29, 2009· Updated Apr 23, 2026
CVE-2009-3894
CVE-2009-3894
Description
Multiple untrusted search path vulnerabilities in dstat before 0.7.0 allow local users to gain privileges via a Trojan horse Python module in (1) the current working directory or (2) a certain subdirectory of the current working directory.
Affected products
24cpe:2.3:a:dag.wieers:dstat:*:*:*:*:*:*:*:*+ 23 more
- cpe:2.3:a:dag.wieers:dstat:*:*:*:*:*:*:*:*range: <=0.6.9
- cpe:2.3:a:dag.wieers:dstat:0.1:*:*:*:*:*:*:*
- cpe:2.3:a:dag.wieers:dstat:0.2:*:*:*:*:*:*:*
- cpe:2.3:a:dag.wieers:dstat:0.3:*:*:*:*:*:*:*
- cpe:2.3:a:dag.wieers:dstat:0.4:*:*:*:*:*:*:*
- cpe:2.3:a:dag.wieers:dstat:0.5:*:*:*:*:*:*:*
- cpe:2.3:a:dag.wieers:dstat:0.5.10:*:*:*:*:*:*:*
- cpe:2.3:a:dag.wieers:dstat:0.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:dag.wieers:dstat:0.5.3:*:*:*:*:*:*:*
- cpe:2.3:a:dag.wieers:dstat:0.5.4:*:*:*:*:*:*:*
- cpe:2.3:a:dag.wieers:dstat:0.5.5:*:*:*:*:*:*:*
- cpe:2.3:a:dag.wieers:dstat:0.5.6:*:*:*:*:*:*:*
- cpe:2.3:a:dag.wieers:dstat:0.5.7:*:*:*:*:*:*:*
- cpe:2.3:a:dag.wieers:dstat:0.5.8:*:*:*:*:*:*:*
- cpe:2.3:a:dag.wieers:dstat:0.5.9:*:*:*:*:*:*:*
- cpe:2.3:a:dag.wieers:dstat:0.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:dag.wieers:dstat:0.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:dag.wieers:dstat:0.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:dag.wieers:dstat:0.6.3:*:*:*:*:*:*:*
- cpe:2.3:a:dag.wieers:dstat:0.6.4:*:*:*:*:*:*:*
- cpe:2.3:a:dag.wieers:dstat:0.6.5:*:*:*:*:*:*:*
- cpe:2.3:a:dag.wieers:dstat:0.6.6:*:*:*:*:*:*:*
- cpe:2.3:a:dag.wieers:dstat:0.6.7:*:*:*:*:*:*:*
- cpe:2.3:a:dag.wieers:dstat:0.6.8:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- www.securityfocus.com/bid/37131nvdPatch
- bugs.gentoo.org/show_bug.cginvd
- osvdb.org/60511nvd
- secunia.com/advisories/37445nvd
- secunia.com/advisories/37457nvd
- security.gentoo.org/glsa/glsa-200911-04.xmlnvd
- svn.rpmforge.net/svn/trunk/tools/dstat/ChangeLognvd
- www.mandriva.com/security/advisoriesnvd
- www.redhat.com/support/errata/RHSA-2009-1619.htmlnvd
- bugzilla.redhat.com/show_bug.cginvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8969nvd
News mentions
0No linked articles in our index yet.