CVE-2009-4013

Publication date 28 January 2010

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

9.8 · Critical

Score breakdown

Description

Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to overwrite arbitrary files or obtain sensitive information via vectors involving (1) control field names, (2) control field values, and (3) control files of patch systems.

Status

Package Ubuntu Release Status
lintian 9.10 karmic
Fixed 2.2.17ubuntu1.1
9.04 jaunty
Fixed 2.2.5ubuntu1.1
8.10 intrepid
Fixed 1.24.3ubuntu0.1
8.04 LTS hardy
Fixed 1.23.46ubuntu0.1
6.06 LTS dapper
Fixed 1.23.16ubuntu2.1

Severity score breakdown

CVSS version: CVSS v3.0

Base score 9.8 · Critical

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Related Ubuntu Security Notices (USN)

    • USN-891-1
    • lintian vulnerabilities
    • 28 January 2010

Other references


Access our resources on patching vulnerabilities