{"id":"DEBIAN-CVE-2009-4261","details":"Multiple directory traversal vulnerabilities in the iallocator framework in Ganeti 1.2.4 through 1.2.8, 2.0.0 through 2.0.4, and 2.1.0 before 2.1.0~rc2 allow (1) remote attackers to execute arbitrary programs via a crafted external script name supplied through the HTTP remote API (RAPI) and allow (2) local users to execute arbitrary programs and gain privileges via a crafted external script name supplied through a gnt-* command, related to \"path sanitization errors.\"","modified":"2026-09-22T16:47:23.673035061Z","published":"2009-12-21T16:30:00.390Z","upstream":["CVE-2009-4261"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2009-4261"}],"affected":[{"package":{"name":"ganeti","ecosystem":"Debian:12","purl":"pkg:deb/debian/ganeti?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.5-1"}]}],"ecosystem_specific":{"urgency":"low"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-4261.json"}},{"package":{"name":"ganeti","ecosystem":"Debian:13","purl":"pkg:deb/debian/ganeti?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.5-1"}]}],"ecosystem_specific":{"urgency":"low"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-4261.json"}}],"schema_version":"1.9.0"}