CVE-2009-2946
published 2009-09-04CVE-2009-2946: Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on…
PriorityP346critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.88%
85.5th percentile
Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | devscripts | < devscripts 2.10.54 (bookworm) | devscripts 2.10.54 (bookworm) |
| devscripts_devel_team | devscripts | >= 0 < 2.10.54 | 2.10.54 |
| devscripts_devel_team | devscripts | >= 0 < 2.10.54 | 2.10.54 |
| devscripts_devel_team | devscripts | >= 0 < 2.10.54 | 2.10.54 |
| devscripts_devel_team | devscripts | >= 0 < 2.10.54 | 2.10.54 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9gf3-j9w5-g3hm: Eval injection vulnerability in scripts/uscan
ghsa_unreviewed·2022-05-02
CVE-2009-2946 [HIGH] GHSA-9gf3-j9w5-g3hm: Eval injection vulnerability in scripts/uscan
Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages.
OSV
CVE-2009-2946: Eval injection vulnerability in scripts/uscan
osv·2009-09-04·CVSS 9.3
CVE-2009-2946 [CRITICAL] CVE-2009-2946: Eval injection vulnerability in scripts/uscan
Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages.
Ubuntu
devscripts vulnerability
vendor_ubuntu·2009-10-09
CVE-2009-2946 devscripts vulnerability
Title: devscripts vulnerability
Summary: devscripts vulnerability
USN-847-1 fixed vulnerabilities in devscripts. This update provides the
corresponding updates for Ubuntu 6.06 LTS.
Original advisory details:
Raphael Geissert discovered that uscan, a part of devscripts, did not
properly sanitize its input when processing pathnames. If uscan processed a
crafted filename for a file on a remote server, an attacker could execute
arbitrary code with the privileges of the user invoking the program.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Ubuntu
Devscripts vulnerability
vendor_ubuntu·2009-10-08
CVE-2009-2946 Devscripts vulnerability
Title: Devscripts vulnerability
Summary: Devscripts vulnerability
Raphael Geissert discovered that uscan, a part of devscripts, did not
properly sanitize its input when processing pathnames. If uscan processed a
crafted filename for a file on a remote server, an attacker could execute
arbitrary code with the privileges of the user invoking the program.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2009-2946: devscripts - Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts a...
vendor_debian·2009·CVSS 9.3
CVE-2009-2946 [CRITICAL] CVE-2009-2946: devscripts - Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts a...
Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages.
Scope: local
bookworm: resolved (fixed in 2.10.54)
bullseye: resolved (fixed in 2.10.54)
forky: resolved (fixed in 2.10.54)
sid: resolved (fixed in 2.10.54)
trixie: resolved (fixed in 2.10.54)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=515209http://svn.debian.org/wsvn/devscripts/trunk/scripts/uscan.pl?op=diff&rev=1984&sc=1http://svn.debian.org/wsvn/devscripts/trunk/scripts/uscan.pl?op=log&rev=0&sc=1&isdir=0http://www.debian.org/security/2009/dsa-1878http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=515209http://svn.debian.org/wsvn/devscripts/trunk/scripts/uscan.pl?op=diff&rev=1984&sc=1http://svn.debian.org/wsvn/devscripts/trunk/scripts/uscan.pl?op=log&rev=0&sc=1&isdir=0http://www.debian.org/security/2009/dsa-1878
2009-09-04
Published