CVE-2012-2241
published 2012-10-01CVE-2012-2241: scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete arbitrary files via a crafted (1) .dsc or (2) .changes file, probably related to…
PriorityP429medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.50%
71.7th percentile
scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete arbitrary files via a crafted (1) .dsc or (2) .changes file, probably related to a NULL byte in a filename.
Affected
93 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | devscripts | < devscripts 2.12.3 (bookworm) | devscripts 2.12.3 (bookworm) |
| devscripts_devel_team | devscripts | <= 2.12.2 | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_ubuntu9.3CRITICAL
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
devscripts vulnerabilities
vendor_ubuntu·2012-10-02·CVSS 9.3
CVE-2012-0212 [CRITICAL] devscripts vulnerabilities
Title: devscripts vulnerabilities
Summary: Several security issues were fixed in devscripts.
Raphael Geissert discovered that the debdiff.pl tool incorrectly handled
shell metacharacters. If a user or automated system were tricked into
processing a specially crafted filename, a remote attacher could possibly
execute arbitrary code. (CVE-2012-0212)
Raphael Geissert discovered that the dscverify tool incorrectly escaped
arguments to external commands. If a user or automated system were tricked
into processing specially crafted files, a remote attacher could possibly
execute arbitrary code. (CVE-2012-2240)
Raphael Geissert discovered that the dget tool incorrectly performed input
validation. If a user or automated system were tricked into processing
specially crafted files, a remote attac
Debian
CVE-2012-2241: devscripts - scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete ar...
vendor_debian·2012·CVSS 5.0
CVE-2012-2241 [MEDIUM] CVE-2012-2241: devscripts - scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete ar...
scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete arbitrary files via a crafted (1) .dsc or (2) .changes file, probably related to a NULL byte in a filename.
Scope: local
bookworm: resolved (fixed in 2.12.3)
bullseye: resolved (fixed in 2.12.3)
forky: resolved (fixed in 2.12.3)
sid: resolved (fixed in 2.12.3)
trixie: resolved (fixed in 2.12.3)
GHSA
GHSA-jfhj-r2mw-3r6p: scripts/dget
ghsa_unreviewed·2022-05-17
CVE-2012-2241 [MEDIUM] CWE-20 GHSA-jfhj-r2mw-3r6p: scripts/dget
scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete arbitrary files via a crafted (1) .dsc or (2) .changes file, probably related to a NULL byte in a filename.
OSV
CVE-2012-2241: scripts/dget
osv·2012-10-01·CVSS 5.0
CVE-2012-2241 [MEDIUM] CVE-2012-2241: scripts/dget
scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete arbitrary files via a crafted (1) .dsc or (2) .changes file, probably related to a NULL byte in a filename.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git%3Ba=commitdiff%3Bh=0fd15bdec07b085f9ef438dacd18e159ac60b810http://secunia.com/advisories/50600http://www.debian.org/security/2012/dsa-2549http://www.securityfocus.com/bid/55564http://www.ubuntu.com/usn/USN-1593-1https://exchange.xforce.ibmcloud.com/vulnerabilities/78977http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git%3Ba=commitdiff%3Bh=0fd15bdec07b085f9ef438dacd18e159ac60b810http://secunia.com/advisories/50600http://www.debian.org/security/2012/dsa-2549http://www.securityfocus.com/bid/55564http://www.ubuntu.com/usn/USN-1593-1https://exchange.xforce.ibmcloud.com/vulnerabilities/78977
2012-10-01
Published