7.5
CVSSv2

CVE-2009-4014

Published: 02/02/2010 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple format string vulnerabilities in Lintian 1.23.x up to and including 1.23.28, 1.24.x up to and including 1.24.2.1, and 2.x prior to 2.3.2 allow remote malicious users to have an unspecified impact via vectors involving (1) check scripts and (2) the Lintian::Schedule module.

Vulnerable Product Search on Vulmon Subscribe to Product

debian lintian 2.2.1

debian lintian 2.2.6

debian lintian 2.2.11

debian lintian 2.1.3

debian lintian 1.23.1

debian lintian 2.1.1

debian lintian 1.23.0

debian lintian 1.23.3

debian lintian 1.23.28

debian lintian 1.23.23

debian lintian 1.23.11

debian lintian 1.24.1

debian lintian 2.2.10

debian lintian 1.23.4

debian lintian 2.2.8

debian lintian 1.23.18

debian lintian 1.23.25

debian lintian 1.24.0

debian lintian 1.23.6

debian lintian 1.23.7

debian lintian 2.1.0

debian lintian 2.1.6

debian lintian 2.1.5

debian lintian 1.23.22

debian lintian 1.23.9

debian lintian 2.2.3

debian lintian 1.23.24

debian lintian 2.3.0

debian lintian 1.24.2

debian lintian 2.1.4

debian lintian 2.2.12

debian lintian 1.23.5

debian lintian 1.23.19

debian lintian 2.2.14

debian lintian 1.23.13

debian lintian 2.2.4

debian lintian 2.2.9

debian lintian 2.0-rc2

debian lintian 1.23.14

debian lintian 2.2.0

debian lintian 1.23.12

debian lintian 2.3.1

debian lintian 2.2.15

debian lintian 1.23.15

debian lintian 2.2.16

debian lintian 1.23.27

debian lintian 1.23.17

debian lintian 1.23.20

debian lintian 2.2.18

debian lintian 1.24.2.1

debian lintian 1.23.10

debian lintian 2.2.2

debian lintian 1.23.8

debian lintian 2.2.5

debian lintian 2.2.13

debian lintian 1.23.26

debian lintian 1.23.2

debian lintian 1.23.16

debian lintian 2.0-rc1

debian lintian 2.2.7

debian lintian 2.1.2

Vendor Advisories

Raphael Geissert discovered that lintian did not correctly validate certain filenames when processing input If a user or an automated system were tricked into running lintian on a specially crafted set of files, a remote attacker could execute arbitrary code with user privileges ...
Multiple vulnerabilities have been discovered in lintian, a Debian package checker The following Common Vulnerabilities and Exposures project ids have been assigned to identify them: CVE-2009-4013: missing control files sanitation Control field names and values were not sanitised before using them in certain operations that could lead to ...