CVE-2009-5043: Critical severity burn project vulnerability
Published Oct 31, 2019
·Updated
burn allows file names to escape via mishandled quotation marks
Affected Software
4 affected components
debian/burn
Burn Project Burn=0.4.6-2
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Event History
Oct 31, 2019
CVE Published
via MITRE·03:28 PM
Data Sourced
via MITRE·03:28 PM
Description
Aug 7, 2024
Data Sourced
via Debian·07:35 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-5043?
The severity of CVE-2009-5043 is classified as medium due to its potential for file name manipulation.
2
What are the affected versions of burn related to CVE-2009-5043?
CVE-2009-5043 affects burn version 0.4.6-2 on Debian GNU/Linux versions 8.0 and 9.0.
3
How do I fix CVE-2009-5043?
To fix CVE-2009-5043, update burn to a patched version that addresses the quotation mark handling issue.
4
What types of systems are vulnerable to CVE-2009-5043?
CVE-2009-5043 primarily affects Debian GNU/Linux systems running the specific version of burn.
5
What is the nature of the vulnerability in CVE-2009-5043?
CVE-2009-5043 allows file names to escape due to mishandled quotation marks, potentially leading to unauthorized file access.