CVE-2012-0212
published 2012-06-16CVE-2012-0212: debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via shell metacharacters in the file…
PriorityP351critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.82%
92.3th percentile
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via shell metacharacters in the file name argument.
Affected
76 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | devscripts | < devscripts 2.11.4 (bookworm) | devscripts 2.11.4 (bookworm) |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_ubuntu9.3CRITICAL
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Glance logs user name and password in cleartext
ghsa·2022-05-05
CVE-2013-0212 [MEDIUM] CWE-200 OpenStack Glance logs user name and password in cleartext
OpenStack Glance logs user name and password in cleartext
store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading the error messages.
GHSA
GHSA-qmmg-7772-cxg7: debdiff
ghsa_unreviewed·2022-05-04
CVE-2012-0212 [HIGH] CWE-20 GHSA-qmmg-7772-cxg7: debdiff
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via shell metacharacters in the file name argument.
OSV
CVE-2012-0212: debdiff
osv·2012-06-16·CVSS 9.3
CVE-2012-0212 [CRITICAL] CVE-2012-0212: debdiff
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via shell metacharacters in the file name argument.
Red Hat
openstack-glance: Backend password leak in Glance error message
vendor_redhat·2013-01-29·CVSS 4.0
CVE-2013-0212 [MEDIUM] CWE-209 openstack-glance: Backend password leak in Glance error message
openstack-glance: Backend password leak in Glance error message
store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading the error messages.
Ubuntu
devscripts vulnerabilities
vendor_ubuntu·2012-10-02·CVSS 9.3
CVE-2012-0212 [CRITICAL] devscripts vulnerabilities
Title: devscripts vulnerabilities
Summary: Several security issues were fixed in devscripts.
Raphael Geissert discovered that the debdiff.pl tool incorrectly handled
shell metacharacters. If a user or automated system were tricked into
processing a specially crafted filename, a remote attacher could possibly
execute arbitrary code. (CVE-2012-0212)
Raphael Geissert discovered that the dscverify tool incorrectly escaped
arguments to external commands. If a user or automated system were tricked
into processing specially crafted files, a remote attacher could possibly
execute arbitrary code. (CVE-2012-2240)
Raphael Geissert discovered that the dget tool incorrectly performed input
validation. If a user or automated system were tricked into processing
specially crafted files, a remote attac
Ubuntu
devscripts vulnerabilities
vendor_ubuntu·2012-02-15·CVSS 9.3
CVE-2012-0210 [CRITICAL] devscripts vulnerabilities
Title: devscripts vulnerabilities
Summary: debdiff, a part of devscripts, could be made to run programs as your login if
it opened a specially crafted file.
Paul Wise discovered that debdiff did not properly sanitize its input when
processing .dsc and .changes files. If debdiff processed a crafted file, an
attacker could execute arbitrary code with the privileges of the user invoking
the program. (CVE-2012-0210)
Raphael Geissert discovered that debdiff did not properly sanitize its input
when processing source packages. If debdiff processed an original source
tarball, with crafted filenames in the top-level directory, an attacker could
execute arbitrary code with the privileges of the user invoking the program.
(CVE-2012-0211)
Raphael Geissert discovered that debdiff did not properly s
Debian
CVE-2012-0212: devscripts - debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows r...
vendor_debian·2012·CVSS 9.3
CVE-2012-0212 [CRITICAL] CVE-2012-0212: devscripts - debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows r...
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via shell metacharacters in the file name argument.
Scope: local
bookworm: resolved (fixed in 2.11.4)
bullseye: resolved (fixed in 2.11.4)
forky: resolved (fixed in 2.11.4)
sid: resolved (fixed in 2.11.4)
trixie: resolved (fixed in 2.11.4)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git%3Ba=commitdiff%3Bh=9cbe605d3eab4f9e67525f69b676c55b273b7a03http://secunia.com/advisories/47955http://secunia.com/advisories/48039http://ubuntu.com/usn/usn-1366-1http://www.debian.org/security/2012/dsa-2409http://www.osvdb.org/79322http://www.securityfocus.com/bid/52029http://www.ubuntu.com/usn/USN-1593-1https://exchange.xforce.ibmcloud.com/vulnerabilities/73217http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git%3Ba=commitdiff%3Bh=9cbe605d3eab4f9e67525f69b676c55b273b7a03http://secunia.com/advisories/47955http://secunia.com/advisories/48039http://ubuntu.com/usn/usn-1366-1http://www.debian.org/security/2012/dsa-2409http://www.osvdb.org/79322http://www.securityfocus.com/bid/52029http://www.ubuntu.com/usn/USN-1593-1https://exchange.xforce.ibmcloud.com/vulnerabilities/73217
2012-06-16
Published