Vulnerability Description
Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to overwrite arbitrary files or obtain sensitive information via vectors involving (1) control field names, (2) control field values, and (3) control files of patch systems.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian | Lintian | >= 1.23.0, <= 1.23.28 |
| Debian | Debian Linux | 4.0 |
| Canonical | Ubuntu Linux | 6.06 |
Related Weaknesses (CWE)
References
- http://git.debian.org/?p=lintian/lintian.git%3Ba=commit%3Bh=c8d01f062b3e5137cf65Broken Link
- http://git.debian.org/?p=lintian/lintian.git%3Ba=commit%3Bh=fbe0c92b2ef7e360d134Broken Link
- http://packages.debian.org/changelogs/pool/main/l/lintian/lintian_2.3.2/changeloBroken Link
- http://packages.qa.debian.org/l/lintian/news/20100128T015554Z.htmlMailing ListPatch
- http://secunia.com/advisories/38375Broken LinkVendor Advisory
- http://secunia.com/advisories/38379Broken LinkVendor Advisory
- http://www.debian.org/security/2010/dsa-1979Third Party Advisory
- http://www.securityfocus.com/bid/37975Broken LinkPatchThird Party Advisory
- http://www.ubuntu.com/usn/USN-891-1Third Party Advisory
- http://git.debian.org/?p=lintian/lintian.git%3Ba=commit%3Bh=c8d01f062b3e5137cf65Broken Link
- http://git.debian.org/?p=lintian/lintian.git%3Ba=commit%3Bh=fbe0c92b2ef7e360d134Broken Link
- http://packages.debian.org/changelogs/pool/main/l/lintian/lintian_2.3.2/changeloBroken Link
- http://packages.qa.debian.org/l/lintian/news/20100128T015554Z.htmlMailing ListPatch
- http://secunia.com/advisories/38375Broken LinkVendor Advisory
- http://secunia.com/advisories/38379Broken LinkVendor Advisory
FAQ
What is CVE-2009-4013?
CVE-2009-4013 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to overwrite arbitrary files or obtain sensitive in...
How severe is CVE-2009-4013?
CVE-2009-4013 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2009-4013?
Check the references section above for vendor advisories and patch information. Affected products include: Debian Lintian, Debian Debian Linux, Canonical Ubuntu Linux.