CVE-2009-2946

EUVD-2009-2933
Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 73%
Affected Products (NVD)
VendorProductVersion
devscripts_devel_teamdevscripts
*
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
devscripts
bookworm
2.23.4+deb12u1
fixed
bullseye
2.21.3+deb11u1
fixed
sid
2.24.2
fixed
trixie
2.24.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
devscripts
dapper
Fixed 2.9.10-0ubuntu0.1
released
hardy
Fixed 2.10.11ubuntu5.8.04.4
released
intrepid
Fixed 2.10.26ubuntu15.2
released
jaunty
Fixed 2.10.39ubuntu7.1
released