PT-2010-1025 · Debian · Lintian

Rg

·

Published

2010-02-02

·

Updated

2010-02-04

·

CVE-2009-4015

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Lintian versions 1.23.x through 1.23.28 Lintian versions 1.24.x through 1.24.2.1 Lintian versions 2.x before 2.3.2
Description The issue allows remote attackers to execute arbitrary commands via shell metacharacters in filename arguments, potentially leading to disruption of confidentiality, integrity, and availability of protected information. This can be exploited remotely.
Recommendations For Lintian versions 1.23.x through 1.23.28, update to a version after 1.23.28 or apply a patch if available. For Lintian versions 1.24.x through 1.24.2.1, update to a version after 1.24.2.1 or apply a patch if available. For Lintian versions 2.x before 2.3.2, update to version 2.3.2 or later.

Fix

Path traversal

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02904
CVE-2009-4015
DSA-1979-1

Affected Products

Lintian