CVE-2015-5652

EUVD-2015-5603
Untrusted search path vulnerability in python.exe in Python through 3.5.0 on Windows allows local users to gain privileges via a Trojan horse readline.pyd file in the current working directory.  NOTE: the vendor says "It was determined that this is a longtime behavior of Python that cannot really be altered at this point."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 34%
Affected Products (NVD)
VendorProductVersion
pythonpython
𝑥
≤ 3.5.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python2.7
bionic
not-affected
cosmic
not-affected
precise
not-affected
trusty
not-affected
vivid
not-affected
xenial
not-affected
python3.2
precise
not-affected
trusty
dne
vivid
dne
python3.4
bionic
dne
cosmic
dne
precise
dne
trusty
not-affected
vivid
not-affected
xenial
dne
python3.5
bionic
dne
cosmic
dne
precise
dne
trusty
not-affected
vivid
dne
xenial
not-affected