PT-2010-1025 · Debian · Lintian
Rg
·
Published
2010-02-02
·
Updated
2010-02-04
·
CVE-2009-4015
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Lintian versions 1.23.x through 1.23.28
Lintian versions 1.24.x through 1.24.2.1
Lintian versions 2.x before 2.3.2
Description
The issue allows remote attackers to execute arbitrary commands via shell metacharacters in filename arguments, potentially leading to disruption of confidentiality, integrity, and availability of protected information. This can be exploited remotely.
Recommendations
For Lintian versions 1.23.x through 1.23.28, update to a version after 1.23.28 or apply a patch if available.
For Lintian versions 1.24.x through 1.24.2.1, update to a version after 1.24.2.1 or apply a patch if available.
For Lintian versions 2.x before 2.3.2, update to version 2.3.2 or later.
Fix
Path traversal
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lintian