PT-2010-1024 · Debian · Lintian
Raphael Geissert
·
Publicado
2010-02-02
·
Atualizado
2010-02-03
·
CVE-2009-4014
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Lintian versions 1.23.x through 1.23.28
Lintian versions 1.24.x through 1.24.2.1
Lintian versions 2.x before 2.3.2
Description
The issue involves multiple format string vulnerabilities that can be exploited remotely. These vulnerabilities are related to (1) check scripts and (2) the Lintian::Schedule module. The exploitation of these vulnerabilities may lead to a breach of confidentiality, integrity, and availability of protected information.
Recommendations
For Lintian versions 1.23.x through 1.23.28, update to a version after 1.23.28.
For Lintian versions 1.24.x through 1.24.2.1, update to a version after 1.24.2.1.
For Lintian versions 2.x before 2.3.2, update to version 2.3.2 or later.
Correção
Use of Externally-Controlled Format String
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Lintian