CVE-2009-4014
published 2010-02-02CVE-2009-4014: Multiple format string vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to have an…
PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.06%
86.3th percentile
Multiple format string vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to have an unspecified impact via vectors involving (1) check scripts and (2) the Lintian::Schedule module.
Affected
66 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | lintian | < lintian 2.3.2 (bookworm) | lintian 2.3.2 (bookworm) |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Debian Lintian up to 1.23.6 Lintian::Schedule format string (Nessus ID 44843 / ID 195038)
vuldb·2026-04-29·CVSS 7.5
CVE-2009-4014 [HIGH] Debian Lintian up to 1.23.6 Lintian::Schedule format string (Nessus ID 44843 / ID 195038)
A vulnerability described as critical has been identified in Debian Lintian up to 1.23.6. This vulnerability affects the function Lintian::Schedule. The manipulation results in format string.
This vulnerability is cataloged as CVE-2009-4014. The attack may be launched remotely. There is no exploit available.
GHSA
GHSA-w9gf-w4gv-5j2q: Multiple format string vulnerabilities in Lintian 1
ghsa_unreviewed·2022-05-02
CVE-2009-4014 [HIGH] CWE-134 GHSA-w9gf-w4gv-5j2q: Multiple format string vulnerabilities in Lintian 1
Multiple format string vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to have an unspecified impact via vectors involving (1) check scripts and (2) the Lintian::Schedule module.
OSV
CVE-2009-4014: Multiple format string vulnerabilities in Lintian 1
osv·2010-02-02·CVSS 7.5
CVE-2009-4014 [HIGH] CVE-2009-4014: Multiple format string vulnerabilities in Lintian 1
Multiple format string vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to have an unspecified impact via vectors involving (1) check scripts and (2) the Lintian::Schedule module.
Ubuntu
lintian vulnerabilities
vendor_ubuntu·2010-01-28
CVE-2009-4015 lintian vulnerabilities
Title: lintian vulnerabilities
Summary: lintian vulnerabilities
Raphael Geissert discovered that lintian did not correctly validate
certain filenames when processing input. If a user or an automated system
were tricked into running lintian on a specially crafted set of files,
a remote attacker could execute arbitrary code with user privileges.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2009-4014: lintian - Multiple format string vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x...
vendor_debian·2009·CVSS 7.5
CVE-2009-4014 [HIGH] CVE-2009-4014: lintian - Multiple format string vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x...
Multiple format string vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to have an unspecified impact via vectors involving (1) check scripts and (2) the Lintian::Schedule module.
Scope: local
bookworm: resolved (fixed in 2.3.2)
bullseye: resolved (fixed in 2.3.2)
forky: resolved (fixed in 2.3.2)
sid: resolved (fixed in 2.3.2)
trixie: resolved (fixed in 2.3.2)
No detection rules found.
No public exploits indexed.
Talos
Rule release for today - January 27th 2009
blogs_talos·2009-01-27·CVSS 10.0
CVE-2008-4006 [CRITICAL] Rule release for today - January 27th 2009
## Rule release for today - January 27th 2009
Large batch of Oracle vulnerabilities today. We've had to work through these carefully as details were pretty scant. Here's what we released:
Oracle Secure Backup Command Injection (CVE-2008-4006) Oracle BPEL Injection (CVE-2008-4014) Oracle Secure Backup Command Injection (CVE-2008-5440) Oracle Secure Backup Buffer Overflow (CVE-2008-5444) Oracle Secure Backup Command Injection (CVE-2008-5448) Oracle Secure Backup Command Injection (CVE-2008-5449) Oracle BEA WebLogic Denial of Service (CVE-2008-5457)
More details can be found here: http://www.snort.org/vrt/advisories/vrt-rules-2009-01-27.html
Talos
Rule release for today - January 27th 2009
blogs_talos·2009-01-27·CVSS 10.0
CVE-2008-4006 [CRITICAL] Rule release for today - January 27th 2009
Large batch of Oracle vulnerabilities today. We've had to work through these carefully as details were pretty scant. Here's what we released:
Oracle Secure Backup Command Injection (CVE-2008-4006)
Oracle BPEL Injection (CVE-2008-4014)
Oracle Secure Backup Command Injection (CVE-2008-5440)
Oracle Secure Backup Buffer Overflow (CVE-2008-5444)
Oracle Secure Backup Command Injection (CVE-2008-5448)
Oracle Secure Backup Command Injection (CVE-2008-5449)
Oracle BEA WebLogic Denial of Service (CVE-2008-5457)
More details can be found here: http://www.snort.org/vrt/advisories/vrt-rules-2009-01-27.html
http://git.debian.org/?p=lintian/lintian.git%3Ba=commit%3Bh=c8d01f062b3e5137cf65196760b079a855c75e00http://git.debian.org/?p=lintian/lintian.git%3Ba=commit%3Bh=fbe0c92b2ef7e360d13414bf40d6af5507d0c86dhttp://packages.debian.org/changelogs/pool/main/l/lintian/lintian_2.3.2/changeloghttp://packages.qa.debian.org/l/lintian/news/20100128T015554Z.htmlhttp://secunia.com/advisories/38375http://secunia.com/advisories/38379http://www.debian.org/security/2010/dsa-1979http://www.securityfocus.com/bid/37975http://www.ubuntu.com/usn/USN-891-1http://git.debian.org/?p=lintian/lintian.git%3Ba=commit%3Bh=c8d01f062b3e5137cf65196760b079a855c75e00http://git.debian.org/?p=lintian/lintian.git%3Ba=commit%3Bh=fbe0c92b2ef7e360d13414bf40d6af5507d0c86dhttp://packages.debian.org/changelogs/pool/main/l/lintian/lintian_2.3.2/changeloghttp://packages.qa.debian.org/l/lintian/news/20100128T015554Z.htmlhttp://secunia.com/advisories/38375http://secunia.com/advisories/38379http://www.debian.org/security/2010/dsa-1979http://www.securityfocus.com/bid/37975http://www.ubuntu.com/usn/USN-891-1
2010-02-02
Published