Comment 1 for bug 1507480

Revision history for this message
Martin Pitt (pitti) wrote :

Gabriel provided a fix for this, by rewriting _python_module_path() in a way to avoid actually importing the module. I created a test case for this which reproduces the issue with unittest.__main__ (which isn't an actual exploit, but sufficient to demonstrate the problem).

Security team, can you please assign a CVE and CRD? Once we agree to this fix, I'll provide backports for earlier Ubuntu stable releases.