Thread: USN-847-2: devscripts vulnerability
referenced cves:
cve-2009-2946
description:
================================================== ========= ubuntu security notice usn-847-2 october 09, 2009 devscripts vulnerability cve-2009-2946 ================================================== ========= security issue affects following ubuntu releases: ubuntu 6.06 lts advisory applies corresponding versions of kubuntu, edubuntu, , xubuntu. problem can corrected upgrading system following package versions: ubuntu 6.06 lts: devscripts 2.9.10-0ubuntu0.1 in general, standard system upgrade sufficient effect necessary changes. details follow: usn-847-1 fixed vulnerabilities in devscripts. update provides corresponding updates ubuntu 6.06 lts. original advisory details: raphael geissert discovered uscan, part of devscripts, did not sanitize input when processing pathnames. if uscan processed crafted filename file on remote server, attacker execute arbitrary code privileges of user invoking program.
more...
Forum The Ubuntu Forum Community Ubuntu Community Discussions Announcements & News USN-847-2: devscripts vulnerability
Ubuntu
Comments
Post a Comment