changetrack 4.3 allows local users to execute arbitrary commands via CRLF sequences and shell metacharacters in a filename in a directory that is checked by changetrack.
Advisories
Source ID Title
Debian DSA Debian DSA DSA-1891-1 New changetrack packages fix arbitrary code execution
EUVD EUVD EUVD-2009-3216 changetrack 4.3 allows local users to execute arbitrary commands via CRLF sequences and shell metacharacters in a filename in a directory that is checked by changetrack.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-17T01:51:03.563Z

Reserved: 2009-09-16T00:00:00Z

Link: CVE-2009-3233

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2009-09-17T10:30:01.280

Modified: 2025-04-09T00:30:58.490

Link: CVE-2009-3233

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses