cbcvebase.
CVE-2009-2946
published 2009-09-04

CVE-2009-2946: Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on…

PriorityP346critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.88%
85.5th percentile
Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages.

Affected

5 ranges
VendorProductVersion rangeFixed in
debiandevscripts< devscripts 2.10.54 (bookworm)devscripts 2.10.54 (bookworm)
devscripts_devel_teamdevscripts>= 0 < 2.10.542.10.54
devscripts_devel_teamdevscripts>= 0 < 2.10.542.10.54
devscripts_devel_teamdevscripts>= 0 < 2.10.542.10.54
devscripts_devel_teamdevscripts>= 0 < 2.10.542.10.54

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.