Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2009-2946
HistorySep 04, 2009 - 8:30 p.m.

CVE-2009-2946

2009-09-0420:30:00
Debian Security Bug Tracker
security-tracker.debian.org
11
cve-2009-2946
scripts/uscan.pl
remote attackers
arbitrary perl code
crafted pathnames
distribution servers
upstream source code
debian gnu/linux packages
vulnerability

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.008

Percentile

81.4%

Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages.

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.008

Percentile

81.4%