Mandriva Linux Security Advisory 2009-059 – Python has a variable called sys.path that contains all paths where Python loads modules by using import scripting procedure. A wrong handling of that variable enables local attackers to execute arbitrary code via Python scripting in the current X-Chat working directory. This update provides fix for that vulnerability.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/75287/MDVSA-2009-059.txt
Source: https://packetstormsecurity.com/files/75287/Mandriva-Linux-Security-Advisory-2009-059.html