Mandriva Linux Security Advisory 2009-046 – Python has a variable called sys.path that contains all paths where Python loads modules by using import scripting procedure. A wrong handling of that variable enables local attackers to execute arbitrary code via Python scripting in the current dia working directory. This update provides fix for that vulnerability. Packages for 2008.0 are being provided due to extended support for Corporate products.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/83592/MDVSA-2009-046-1.txt
Source: https://packetstormsecurity.com/files/83592/Mandriva-Linux-Security-Advisory-2009-046.html

