7.5
CVSSv2

CVE-2009-4015

Published: 02/02/2010 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Lintian 1.23.x up to and including 1.23.28, 1.24.x up to and including 1.24.2.1, and 2.x prior to 2.3.2 allows remote malicious users to execute arbitrary commands via shell metacharacters in filename arguments.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian lintian 2.2.1

debian lintian 2.2.6

debian lintian 2.2.11

debian lintian 2.1.3

debian lintian 1.23.1

debian lintian 2.1.1

debian lintian 1.23.0

debian lintian 1.23.3

debian lintian 1.23.28

debian lintian 1.23.23

debian lintian 1.23.11

debian lintian 1.24.1

debian lintian 2.2.10

debian lintian 1.23.4

debian lintian 2.2.8

debian lintian 1.23.18

debian lintian 1.23.25

debian lintian 1.24.0

debian lintian 1.23.6

debian lintian 1.23.7

debian lintian 2.1.0

debian lintian 2.1.6

debian lintian 2.1.5

debian lintian 1.23.22

debian lintian 1.23.9

debian lintian 2.2.3

debian lintian 1.23.24

debian lintian 2.3.0

debian lintian 1.24.2

debian lintian 2.1.4

debian lintian 2.2.12

debian lintian 1.23.5

debian lintian 1.23.19

debian lintian 2.2.14

debian lintian 1.23.13

debian lintian 2.2.4

debian lintian 2.2.9

debian lintian 2.0-rc2

debian lintian 1.23.14

debian lintian 2.2.0

debian lintian 1.23.12

debian lintian 2.3.1

debian lintian 2.2.15

debian lintian 1.23.15

debian lintian 2.2.16

debian lintian 1.23.27

debian lintian 1.23.17

debian lintian 1.23.20

debian lintian 2.2.18

debian lintian 1.23.10

debian lintian 2.2.2

debian lintian 1.23.8

debian lintian 2.2.5

debian lintian 2.2.13

debian lintian 1.23.26

debian lintian 1.23.2

debian lintian 1.23.16

debian lintian 2.0-rc1

debian lintian 2.2.7

debian lintian 2.1.2

Vendor Advisories

Raphael Geissert discovered that lintian did not correctly validate certain filenames when processing input If a user or an automated system were tricked into running lintian on a specially crafted set of files, a remote attacker could execute arbitrary code with user privileges ...
Multiple vulnerabilities have been discovered in lintian, a Debian package checker The following Common Vulnerabilities and Exposures project ids have been assigned to identify them: CVE-2009-4013: missing control files sanitation Control field names and values were not sanitised before using them in certain operations that could lead to ...