CVE-2017-8829

Deserialization vulnerability in lintian through 2.5.50.3 allows attackers to trigger code execution by requesting a review of a source package with a crafted YAML file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 59%
VendorProductVersion
debianlintian
𝑥
≤ 2.5.50.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
lintian
bullseye
2.104.0
fixed
jessie
not-affected
wheezy
not-affected
bookworm
2.116.3
fixed
trixie
2.119.0
fixed
sid
2.120.0
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
lintian
zesty
Fixed 2.5.50.1ubuntu0.1
released
yakkety
Fixed 2.5.48ubuntu0.1
released
xenial
Fixed 2.5.43ubuntu0.1
released
trusty
not-affected
precise
not-affected