PT-2009-5293 · Debian · Devscripts
Raphael Geissert
·
Published
2009-09-04
·
Updated
2009-09-08
·
CVE-2009-2946
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
devscripts versions prior to Rev 1984
Description:
The issue allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages. This is due to an eval injection vulnerability in the scripts/uscan.pl script.
Recommendations:
For devscripts versions prior to Rev 1984, update to a version that includes the fix for this issue, specifically Rev 1984 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Devscripts