CVE-2009-2946

Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
VendorProductVersion
devscripts_devel_teamdevscripts
*
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
devscripts
bullseye
2.21.3+deb11u1
fixed
bookworm
2.23.4+deb12u1
fixed
trixie
2.24.1
fixed
sid
2.24.2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
devscripts
jaunty
Fixed 2.10.39ubuntu7.1
released
intrepid
Fixed 2.10.26ubuntu15.2
released
hardy
Fixed 2.10.11ubuntu5.8.04.4
released
dapper
Fixed 2.9.10-0ubuntu0.1
released