Deserialization Vulnerability in Lintian Affects Debian Systems
CVE-2017-8829

7.8HIGH

Key Information:

Vendor
Debian
Status
Vendor
CVE Published:
8 May 2017

Summary

A deserialization vulnerability exists in Lintian, a package checker for Debian-based systems, that allows attackers to execute arbitrary code. By submitting a maliciously crafted YAML file during the review of a source package, an attacker can manipulate the deserialization process, leading to potential code execution. This issue highlights the risks associated with improper handling of user input and emphasizes the need for stringent validation mechanisms.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.