CVE Vulnerabilities

CVE-2009-5043

Improper Handling of Exceptional Conditions

Published: Oct 31, 2019 | Modified: Nov 06, 2019
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

burn allows file names to escape via mishandled quotation marks

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

Name Vendor Start Version End Version
Burn Burn_project 0.4.6-2 (including) 0.4.6-2 (including)

References