CVE-2012-0211
published 2012-06-16CVE-2012-0211: debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via a crafted tarball file name in…
PriorityP350critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.82%
92.3th percentile
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via a crafted tarball file name in the top-level directory of an original (.orig) source tarball of a source package.
Affected
75 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | devscripts | < devscripts 2.11.4 (bookworm) | devscripts 2.11.4 (bookworm) |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
devscripts vulnerabilities
vendor_ubuntu·2012-02-15·CVSS 9.3
CVE-2012-0210 [CRITICAL] devscripts vulnerabilities
Title: devscripts vulnerabilities
Summary: debdiff, a part of devscripts, could be made to run programs as your login if
it opened a specially crafted file.
Paul Wise discovered that debdiff did not properly sanitize its input when
processing .dsc and .changes files. If debdiff processed a crafted file, an
attacker could execute arbitrary code with the privileges of the user invoking
the program. (CVE-2012-0210)
Raphael Geissert discovered that debdiff did not properly sanitize its input
when processing source packages. If debdiff processed an original source
tarball, with crafted filenames in the top-level directory, an attacker could
execute arbitrary code with the privileges of the user invoking the program.
(CVE-2012-0211)
Raphael Geissert discovered that debdiff did not properly s
Debian
CVE-2012-0211: devscripts - debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows r...
vendor_debian·2012·CVSS 9.3
CVE-2012-0211 [CRITICAL] CVE-2012-0211: devscripts - debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows r...
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via a crafted tarball file name in the top-level directory of an original (.orig) source tarball of a source package.
Scope: local
bookworm: resolved (fixed in 2.11.4)
bullseye: resolved (fixed in 2.11.4)
forky: resolved (fixed in 2.11.4)
sid: resolved (fixed in 2.11.4)
trixie: resolved (fixed in 2.11.4)
GHSA
GHSA-hwmp-fjcm-wrhx: debdiff
ghsa_unreviewed·2022-05-04
CVE-2012-0211 [HIGH] CWE-20 GHSA-hwmp-fjcm-wrhx: debdiff
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via a crafted tarball file name in the top-level directory of an original (.orig) source tarball of a source package.
OSV
CVE-2012-0211: debdiff
osv·2012-06-16·CVSS 9.3
CVE-2012-0211 [CRITICAL] CVE-2012-0211: debdiff
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via a crafted tarball file name in the top-level directory of an original (.orig) source tarball of a source package.
No detection rules found.
No public exploits indexed.
http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git%3Ba=commitdiff%3Bh=87f88232eb643f0c118c6ba38db8e966915b450fhttp://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git%3Ba=commitdiff%3Bh=9cbe605d3eab4f9e67525f69b676c55b273b7a03http://secunia.com/advisories/47955http://secunia.com/advisories/48039http://ubuntu.com/usn/usn-1366-1http://www.debian.org/security/2012/dsa-2409http://www.osvdb.org/79320http://www.securityfocus.com/bid/52029https://exchange.xforce.ibmcloud.com/vulnerabilities/73216http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git%3Ba=commitdiff%3Bh=87f88232eb643f0c118c6ba38db8e966915b450fhttp://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git%3Ba=commitdiff%3Bh=9cbe605d3eab4f9e67525f69b676c55b273b7a03http://secunia.com/advisories/47955http://secunia.com/advisories/48039http://ubuntu.com/usn/usn-1366-1http://www.debian.org/security/2012/dsa-2409http://www.osvdb.org/79320http://www.securityfocus.com/bid/52029https://exchange.xforce.ibmcloud.com/vulnerabilities/73216
2012-06-16
Published