CVE-2009-0367

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
05/03/2009
Last modified:
09/04/2025

Description

The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by using a whitelisted module that imports an unsafe module, then using a hierarchical module name to access the unsafe module through the whitelisted module.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wesnoth:wesnoth:1.4:*:*:*:*:*:*:*
cpe:2.3:a:wesnoth:wesnoth:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:wesnoth:wesnoth:1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:wesnoth:wesnoth:1.4.3:*:*:*:*:*:*:*
cpe:2.3:a:wesnoth:wesnoth:1.4.4:*:*:*:*:*:*:*
cpe:2.3:a:wesnoth:wesnoth:1.4.5:*:*:*:*:*:*:*
cpe:2.3:a:wesnoth:wesnoth:1.4.6:*:*:*:*:*:*:*
cpe:2.3:a:wesnoth:wesnoth:1.4.7:*:*:*:*:*:*:*
cpe:2.3:a:wesnoth:wesnoth:1.5.0:*:*:*:*:*:*:*
cpe:2.3:a:wesnoth:wesnoth:1.5.1:*:*:*:*:*:*:*
cpe:2.3:a:wesnoth:wesnoth:1.5.2:*:*:*:*:*:*:*
cpe:2.3:a:wesnoth:wesnoth:1.5.3:*:*:*:*:*:*:*
cpe:2.3:a:wesnoth:wesnoth:1.5.4:*:*:*:*:*:*:*
cpe:2.3:a:wesnoth:wesnoth:1.5.5:*:*:*:*:*:*:*
cpe:2.3:a:wesnoth:wesnoth:1.5.6:*:*:*:*:*:*:*