CVE-2009-2946

UnknownEPSS 2.88%

Last modified

CVE-2009-2946 is a vulnerability of currently unknown severity. Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages.. EPSS estimates a 2.88% chance of exploitation in the next 30 days.

Description

Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages.

Metrics

EPSS Probability
2.88%

85.1th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
Devscripts Devel TeamDevscriptsAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2009-2946?
Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages.
How severe is CVE-2009-2946?
Severity scoring for CVE-2009-2946 is pending analysis. The EPSS model estimates a 2.88% probability of exploitation in the next 30 days.
How do I fix CVE-2009-2946?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2009-2946?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST