7.5
CVSSv2

CVE-2009-4013

Published: 02/02/2010 Updated: 26/01/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple directory traversal vulnerabilities in Lintian 1.23.x up to and including 1.23.28, 1.24.x up to and including 1.24.2.1, and 2.x prior to 2.3.2 allow remote malicious users to overwrite arbitrary files or obtain sensitive information via vectors involving (1) control field names, (2) control field values, and (3) control files of patch systems.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian lintian

debian debian linux 5.0

debian debian linux 4.0

canonical ubuntu linux 9.04

canonical ubuntu linux 8.10

canonical ubuntu linux 9.10

canonical ubuntu linux 8.04

canonical ubuntu linux 6.06

Vendor Advisories

Raphael Geissert discovered that lintian did not correctly validate certain filenames when processing input If a user or an automated system were tricked into running lintian on a specially crafted set of files, a remote attacker could execute arbitrary code with user privileges ...
Multiple vulnerabilities have been discovered in lintian, a Debian package checker The following Common Vulnerabilities and Exposures project ids have been assigned to identify them: CVE-2009-4013: missing control files sanitation Control field names and values were not sanitised before using them in certain operations that could lead to ...