PT-2009-5293 · Debian · Devscripts

Raphael Geissert

·

Publicado

2009-09-04

·

Atualizado

2009-09-08

·

CVE-2009-2946

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: devscripts versions prior to Rev 1984
Description: The issue allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages. This is due to an eval injection vulnerability in the scripts/uscan.pl script.
Recommendations: For devscripts versions prior to Rev 1984, update to a version that includes the fix for this issue, specifically Rev 1984 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2009-2946
DSA-1878-1
DSA-1878-2

Produtos afetados

Devscripts