CVE-2009-4015
published 2010-02-02CVE-2009-4015: Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allows remote attackers to execute arbitrary commands via shell metacharacters in…
PriorityP347high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.90%
89.2th percentile
Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allows remote attackers to execute arbitrary commands via shell metacharacters in filename arguments.
Affected
65 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | lintian | < lintian 2.3.2 (bookworm) | lintian 2.3.2 (bookworm) |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
| debian | lintian | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Debian Lintian up to 1.23.6 sql injection (Nessus ID 44843 / ID 195038)
vuldb·2026-04-29·CVSS 7.5
CVE-2009-4015 [HIGH] Debian Lintian up to 1.23.6 sql injection (Nessus ID 44843 / ID 195038)
A vulnerability classified as critical has been found in Debian Lintian up to 1.23.6. This issue affects some unknown processing. This manipulation causes sql injection.
This vulnerability is registered as CVE-2009-4015. Remote exploitation of the attack is possible. No exploit is available.
GHSA
GHSA-f866-mhcw-m7pp: Lintian 1
ghsa_unreviewed·2022-05-02
CVE-2009-4015 [HIGH] CWE-89 GHSA-f866-mhcw-m7pp: Lintian 1
Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allows remote attackers to execute arbitrary commands via shell metacharacters in filename arguments.
OSV
CVE-2009-4015: Lintian 1
osv·2010-02-02·CVSS 7.5
CVE-2009-4015 [HIGH] CVE-2009-4015: Lintian 1
Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allows remote attackers to execute arbitrary commands via shell metacharacters in filename arguments.
Ubuntu
lintian vulnerabilities
vendor_ubuntu·2010-01-28
CVE-2009-4015 lintian vulnerabilities
Title: lintian vulnerabilities
Summary: lintian vulnerabilities
Raphael Geissert discovered that lintian did not correctly validate
certain filenames when processing input. If a user or an automated system
were tricked into running lintian on a specially crafted set of files,
a remote attacker could execute arbitrary code with user privileges.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2009-4015: lintian - Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 al...
vendor_debian·2009·CVSS 7.5
CVE-2009-4015 [HIGH] CVE-2009-4015: lintian - Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 al...
Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allows remote attackers to execute arbitrary commands via shell metacharacters in filename arguments.
Scope: local
bookworm: resolved (fixed in 2.3.2)
bullseye: resolved (fixed in 2.3.2)
forky: resolved (fixed in 2.3.2)
sid: resolved (fixed in 2.3.2)
trixie: resolved (fixed in 2.3.2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://git.debian.org/?p=lintian/lintian.git%3Ba=commit%3Bh=c8d01f062b3e5137cf65196760b079a855c75e00http://git.debian.org/?p=lintian/lintian.git%3Ba=commit%3Bh=fbe0c92b2ef7e360d13414bf40d6af5507d0c86dhttp://packages.debian.org/changelogs/pool/main/l/lintian/lintian_2.3.2/changeloghttp://packages.qa.debian.org/l/lintian/news/20100128T015554Z.htmlhttp://secunia.com/advisories/38375http://secunia.com/advisories/38379http://www.debian.org/security/2010/dsa-1979http://www.securityfocus.com/bid/37975http://www.ubuntu.com/usn/USN-891-1http://git.debian.org/?p=lintian/lintian.git%3Ba=commit%3Bh=c8d01f062b3e5137cf65196760b079a855c75e00http://git.debian.org/?p=lintian/lintian.git%3Ba=commit%3Bh=fbe0c92b2ef7e360d13414bf40d6af5507d0c86dhttp://packages.debian.org/changelogs/pool/main/l/lintian/lintian_2.3.2/changeloghttp://packages.qa.debian.org/l/lintian/news/20100128T015554Z.htmlhttp://secunia.com/advisories/38375http://secunia.com/advisories/38379http://www.debian.org/security/2010/dsa-1979http://www.securityfocus.com/bid/37975http://www.ubuntu.com/usn/USN-891-1
2010-02-02
Published