CVE-2009-2946: Critical severity Devscripts Devel Team Devscripts vulnerability
Published Sep 4, 2009
·Updated
Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages.
Affected Software
2 affected components
Devscripts Devel Team Devscripts
Debian Linux
Event History
Sep 4, 2009
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
08:30 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-2946?
CVE-2009-2946 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2009-2946?
To fix CVE-2009-2946, update devscripts to version 2.10.67 or later.
3
What types of systems are impacted by CVE-2009-2946?
CVE-2009-2946 affects Debian systems using affected versions of the devscripts package.
4
Can CVE-2009-2946 be exploited remotely?
Yes, CVE-2009-2946 can be exploited remotely by attackers who supply crafted pathnames.
5
What is the nature of the vulnerability in CVE-2009-2946?
The vulnerability in CVE-2009-2946 is an eval injection that allows execution of arbitrary Perl code.