CVE-2012-0210
published 2012-06-16CVE-2012-0210: debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to obtain system information and execute arbitrary code via the…
PriorityP348critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.27%
91.6th percentile
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to obtain system information and execute arbitrary code via the file name in a (1) .dsc or (2) .changes file.
Affected
75 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | devscripts | < devscripts 2.11.4 (bookworm) | devscripts 2.11.4 (bookworm) |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
devscripts vulnerabilities
vendor_ubuntu·2012-02-15·CVSS 9.3
CVE-2012-0210 [CRITICAL] devscripts vulnerabilities
Title: devscripts vulnerabilities
Summary: debdiff, a part of devscripts, could be made to run programs as your login if
it opened a specially crafted file.
Paul Wise discovered that debdiff did not properly sanitize its input when
processing .dsc and .changes files. If debdiff processed a crafted file, an
attacker could execute arbitrary code with the privileges of the user invoking
the program. (CVE-2012-0210)
Raphael Geissert discovered that debdiff did not properly sanitize its input
when processing source packages. If debdiff processed an original source
tarball, with crafted filenames in the top-level directory, an attacker could
execute arbitrary code with the privileges of the user invoking the program.
(CVE-2012-0211)
Raphael Geissert discovered that debdiff did not properly s
Debian
CVE-2012-0210: devscripts - debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows r...
vendor_debian·2012·CVSS 9.3
CVE-2012-0210 [CRITICAL] CVE-2012-0210: devscripts - debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows r...
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to obtain system information and execute arbitrary code via the file name in a (1) .dsc or (2) .changes file.
Scope: local
bookworm: resolved (fixed in 2.11.4)
bullseye: resolved (fixed in 2.11.4)
forky: resolved (fixed in 2.11.4)
sid: resolved (fixed in 2.11.4)
trixie: resolved (fixed in 2.11.4)
GHSA
GHSA-jffw-h3p9-v55c: debdiff
ghsa_unreviewed·2022-05-04
CVE-2012-0210 [HIGH] CWE-20 GHSA-jffw-h3p9-v55c: debdiff
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to obtain system information and execute arbitrary code via the file name in a (1) .dsc or (2) .changes file.
OSV
CVE-2012-0210: debdiff
osv·2012-06-16·CVSS 9.3
CVE-2012-0210 [CRITICAL] CVE-2012-0210: debdiff
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to obtain system information and execute arbitrary code via the file name in a (1) .dsc or (2) .changes file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git%3Ba=commitdiff%3Bh=797ddc961532eb0aeb46153e3f28c8e9ea0500d2http://secunia.com/advisories/47955http://secunia.com/advisories/48039http://ubuntu.com/usn/usn-1366-1http://www.debian.org/security/2012/dsa-2409http://www.osvdb.org/79319http://www.securityfocus.com/bid/52029https://exchange.xforce.ibmcloud.com/vulnerabilities/73215http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git%3Ba=commitdiff%3Bh=797ddc961532eb0aeb46153e3f28c8e9ea0500d2http://secunia.com/advisories/47955http://secunia.com/advisories/48039http://ubuntu.com/usn/usn-1366-1http://www.debian.org/security/2012/dsa-2409http://www.osvdb.org/79319http://www.securityfocus.com/bid/52029https://exchange.xforce.ibmcloud.com/vulnerabilities/73215
2012-06-16
Published