← Back

Lintian

lintian

Vendor: Debian • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Canonical
Debian
3Debian Linux
LintianUbuntu Linux
Nov 21, 2024
Nov 7, 2019
N/A· v4
6.3 MEDIUM· v3
4.3 MEDIUM· v2
Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks.
1Debian
1Lintian
May 13, 2026
May 8, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Deserialization vulnerability in lintian through 2.5.50.3 allows attackers to trigger code execution by requesting a review of a source package with a crafted YAML file.
1Debian
1Lintian
Apr 29, 2026
Feb 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allows remote attackers to execute arbitrary commands via shell metacharacters in filename arguments.
1Debian
1Lintian
Apr 29, 2026
Feb 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple format string vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to have an unspecified impact via vectors involving (1) check scripts and (2)...Show more
Multiple format string vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to have an unspecified impact via vectors involving (1) check scripts and (2) the Lintian::Schedule module.Show less
2Canonical
Debian
3Debian Linux
LintianUbuntu Linux
Apr 29, 2026
Feb 2, 2010
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to overwrite arbitrary files or obtain sensitive information via vector...Show more
Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to overwrite arbitrary files or obtain sensitive information via vectors involving (1) control field names, (2) control field values, and (3) control files of patch systems.Show less
1Debian
1Lintian
Apr 16, 2026
Jan 10, 2004
N/A· v4
N/A· v3
2.1 LOW· v2
lintian 1.23 and earlier removes the working directory even if it was not created by lintian, which may allow local users to delete arbitrary files or directories via a symlink attack.