PT-2010-1024 · Debian · Lintian

Raphael Geissert

·

Publicado

2010-02-02

·

Atualizado

2010-02-03

·

CVE-2009-4014

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Lintian versions 1.23.x through 1.23.28 Lintian versions 1.24.x through 1.24.2.1 Lintian versions 2.x before 2.3.2
Description The issue involves multiple format string vulnerabilities that can be exploited remotely. These vulnerabilities are related to (1) check scripts and (2) the Lintian::Schedule module. The exploitation of these vulnerabilities may lead to a breach of confidentiality, integrity, and availability of protected information.
Recommendations For Lintian versions 1.23.x through 1.23.28, update to a version after 1.23.28. For Lintian versions 1.24.x through 1.24.2.1, update to a version after 1.24.2.1. For Lintian versions 2.x before 2.3.2, update to version 2.3.2 or later.

Correção

Use of Externally-Controlled Format String

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-02904
CVE-2009-4014
DSA-1979-1

Produtos afetados

Lintian