CVE-2009-2946
devscripts - regression fix
EPSS 2.9%
描述
Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages.
如何修補 CVE-2009-2946
要修補 CVE-2009-2946,請將受影響套件升級到下列已修補版本。
- Debian/devscripts—升級至 2.10.54 或更新版本
- Debian/devscripts—升級至 2.9.26etch4 或更新版本
- Debian/devscripts—升級至 2.9.26etch5 或更新版本
CVE-2009-2946 正在被利用嗎?
低 — EPSS 為 2.9%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 2.10.54
- from 0, < 2.9.26etch4
- from 0, < 2.9.26etch5