CVE-2009-4013
Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to overwrite arbitrary files or obtain sensitive information via vectors involving (1) control field…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.68%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to overwrite arbitrary files or obtain sensitive information via vectors involving (1) control field names, (2) control field values, and (3) control files of patch systems.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 5.68% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- debian/lintian · debian/debian linux · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://git.debian.org/?p=lintian/lintian.git%3Ba=commit%3Bh=c8d01f062b3e5137cf65196760b079a855c75e00Broken Link
- http://git.debian.org/?p=lintian/lintian.git%3Ba=commit%3Bh=fbe0c92b2ef7e360d13414bf40d6af5507d0c86dBroken Link
- http://packages.debian.org/changelogs/pool/main/l/lintian/lintian_2.3.2/changelogBroken Link
- http://packages.qa.debian.org/l/lintian/news/20100128T015554Z.htmlMailing List, Patch
- http://secunia.com/advisories/38375Broken Link, Vendor Advisory
- http://secunia.com/advisories/38379Broken Link, Vendor Advisory
- http://www.debian.org/security/2010/dsa-1979Third Party Advisory
- http://www.securityfocus.com/bid/37975Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-891-1Third Party Advisory
- http://git.debian.org/?p=lintian/lintian.git%3Ba=commit%3Bh=c8d01f062b3e5137cf65196760b079a855c75e00Broken Link
- http://git.debian.org/?p=lintian/lintian.git%3Ba=commit%3Bh=fbe0c92b2ef7e360d13414bf40d6af5507d0c86dBroken Link
- http://packages.debian.org/changelogs/pool/main/l/lintian/lintian_2.3.2/changelogBroken Link
- http://packages.qa.debian.org/l/lintian/news/20100128T015554Z.htmlMailing List, Patch
- http://secunia.com/advisories/38375Broken Link, Vendor Advisory
- http://secunia.com/advisories/38379Broken Link, Vendor Advisory
- http://www.debian.org/security/2010/dsa-1979Third Party Advisory
- http://www.securityfocus.com/bid/37975Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-891-1Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.