{ "schema_version": "1.4.0", "id": "GHSA-f866-mhcw-m7pp", "modified": "2025-04-11T03:31:12Z", "published": "2022-05-02T03:50:42Z", "aliases": [ "CVE-2009-4015" ], "details": "Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allows remote attackers to execute arbitrary commands via shell metacharacters in filename arguments.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2009-4015" }, { "type": "WEB", "url": "http://git.debian.org/?p=lintian/lintian.git%3Ba=commit%3Bh=c8d01f062b3e5137cf65196760b079a855c75e00" }, { "type": "WEB", "url": "http://git.debian.org/?p=lintian/lintian.git%3Ba=commit%3Bh=fbe0c92b2ef7e360d13414bf40d6af5507d0c86d" }, { "type": "WEB", "url": "http://git.debian.org/?p=lintian/lintian.git;a=commit;h=c8d01f062b3e5137cf65196760b079a855c75e00" }, { "type": "WEB", "url": "http://git.debian.org/?p=lintian/lintian.git;a=commit;h=fbe0c92b2ef7e360d13414bf40d6af5507d0c86d" }, { "type": "WEB", "url": "http://packages.debian.org/changelogs/pool/main/l/lintian/lintian_2.3.2/changelog" }, { "type": "WEB", "url": "http://packages.qa.debian.org/l/lintian/news/20100128T015554Z.html" }, { "type": "WEB", "url": "http://secunia.com/advisories/38375" }, { "type": "WEB", "url": "http://secunia.com/advisories/38379" }, { "type": "WEB", "url": "http://www.debian.org/security/2010/dsa-1979" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/37975" }, { "type": "WEB", "url": "http://www.ubuntu.com/usn/USN-891-1" } ], "database_specific": { "cwe_ids": [ "CWE-89" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2010-02-02T16:30:00Z" } }