CVE-2009-0367 describes a critical sandbox escape vulnerability in the Python AI module of Wesnoth versions 1.4.x and 1.5 prior to 1.5.11. Remote attackers can exploit this by leveraging a whitelisted module to import and then access an unsafe module, leading to arbitrary code execution. With a CVSS score of 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C), this vulnerability is highly severe, indicating network-based attacks with medium complexity that can result in complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog and lacking social media discussion or media coverage, an exploit (EDB-32837) is publicly available, suggesting potential for exploitation despite its age.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4CPE matchmatch criteria | cpe:2.3:a:wesnoth:wesnoth:1.4:*:*:*:*:*:*:* | ||
1.4.1CPE matchmatch criteria | cpe:2.3:a:wesnoth:wesnoth:1.4.1:*:*:*:*:*:*:* | ||
1.4.2CPE matchmatch criteria | cpe:2.3:a:wesnoth:wesnoth:1.4.2:*:*:*:*:*:*:* | ||
1.4.3CPE matchmatch criteria | cpe:2.3:a:wesnoth:wesnoth:1.4.3:*:*:*:*:*:*:* | ||
1.4.4CPE matchmatch criteria | cpe:2.3:a:wesnoth:wesnoth:1.4.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.