CVE-2005-1632
Cheetah Path Search Order Hijacking
EPSS 0.05%
Description
Cheetah 0.9.15 and 0.9.16 searches the `/tmp` directory for modules before using the paths in the `PYTHONPATH` variable, which allows local users to execute arbitrary code via a malicious module in `/tmp/`.
How to fix CVE-2005-1632
To remediate CVE-2005-1632, upgrade the affected package to a fixed version below.
- Debian/cheetah—upgrade to 0.9.16-1 or later
- PyPI/cheetah—no fix listed
Is CVE-2005-1632 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 0.9.16-1
- >= 0.9.15, <= 0.9.16