Untrusted search path vulnerability in Catfish through 0.4.0.3 allows local users to gain privileges via a Trojan horse catfish.py in the current working directory. Per: http://cwe.mitre.org/data/definitions/426.html
"CWE-426: Untrusted Search Path"
Publication date: Wed, 26 Feb 2014 20:55:00 +0000