PT-2009-5293 · Debian · Devscripts

Raphael Geissert

·

Published

2009-09-04

·

Updated

2009-09-08

·

CVE-2009-2946

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: devscripts versions prior to Rev 1984
Description: The issue allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages. This is due to an eval injection vulnerability in the scripts/uscan.pl script.
Recommendations: For devscripts versions prior to Rev 1984, update to a version that includes the fix for this issue, specifically Rev 1984 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2009-2946
DSA-1878-1
DSA-1878-2

Affected Products

Devscripts