Deserialization Vulnerability in Lintian Affects Debian Systems
CVE-2017-8829
7.8HIGH
Summary
A deserialization vulnerability exists in Lintian, a package checker for Debian-based systems, that allows attackers to execute arbitrary code. By submitting a maliciously crafted YAML file during the review of a source package, an attacker can manipulate the deserialization process, leading to potential code execution. This issue highlights the risks associated with improper handling of user input and emphasizes the need for stringent validation mechanisms.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved