Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allows remote attackers to execute arbitrary commands via shell metacharacters in filename arguments.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:08
Type | Values Removed | Values Added |
---|---|---|
References | () http://git.debian.org/?p=lintian/lintian.git%3Ba=commit%3Bh=c8d01f062b3e5137cf65196760b079a855c75e00 - | |
References | () http://git.debian.org/?p=lintian/lintian.git%3Ba=commit%3Bh=fbe0c92b2ef7e360d13414bf40d6af5507d0c86d - | |
References | () http://packages.debian.org/changelogs/pool/main/l/lintian/lintian_2.3.2/changelog - | |
References | () http://packages.qa.debian.org/l/lintian/news/20100128T015554Z.html - | |
References | () http://secunia.com/advisories/38375 - Vendor Advisory | |
References | () http://secunia.com/advisories/38379 - Vendor Advisory | |
References | () http://www.debian.org/security/2010/dsa-1979 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/37975 - Patch | |
References | () http://www.ubuntu.com/usn/USN-891-1 - |
07 Nov 2023, 02:04
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2010-02-02 16:30
Updated : 2024-11-21 01:08
NVD link : CVE-2009-4015
Mitre link : CVE-2009-4015
CVE.ORG link : CVE-2009-4015
JSON object : View
Products Affected
debian
- lintian
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')