CVE-2013-6888
published 2014-01-07CVE-2013-6888: Uscan in devscripts before 2.13.9 allows remote attackers to execute arbitrary code via a crafted tarball.
PriorityP345high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.09%
89.6th percentile
Uscan in devscripts before 2.13.9 allows remote attackers to execute arbitrary code via a crafted tarball.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | devscripts | < devscripts 2.13.9 (bookworm) | devscripts 2.13.9 (bookworm) |
| devscripts_devel_team | devscripts | <= 2.13.8 | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | — | — |
| devscripts_devel_team | devscripts | >= 0 < 2.13.9 | 2.13.9 |
| devscripts_devel_team | devscripts | >= 0 < 2.13.9 | 2.13.9 |
| devscripts_devel_team | devscripts | >= 0 < 2.13.9 | 2.13.9 |
| devscripts_devel_team | devscripts | >= 0 < 2.13.9 | 2.13.9 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
devscripts vulnerability
vendor_ubuntu·2014-01-21
CVE-2013-6888 devscripts vulnerability
Title: devscripts vulnerability
Summary: devscripts could be made to run programs if it opened a specially crafted
file.
It was discovered that the uscan tool incorrectly repacked archive files.
If a user or automated system were tricked into processing specially
crafted files, a remote attacker could possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2013-6888: devscripts - Uscan in devscripts before 2.13.9 allows remote attackers to execute arbitrary c...
vendor_debian·2013·CVSS 7.5
CVE-2013-6888 [HIGH] CVE-2013-6888: devscripts - Uscan in devscripts before 2.13.9 allows remote attackers to execute arbitrary c...
Uscan in devscripts before 2.13.9 allows remote attackers to execute arbitrary code via a crafted tarball.
Scope: local
bookworm: resolved (fixed in 2.13.9)
bullseye: resolved (fixed in 2.13.9)
forky: resolved (fixed in 2.13.9)
sid: resolved (fixed in 2.13.9)
trixie: resolved (fixed in 2.13.9)
GHSA
GHSA-5xpf-9vwg-2chq: Uscan in devscripts before 2
ghsa_unreviewed·2022-05-17
CVE-2013-6888 [HIGH] GHSA-5xpf-9vwg-2chq: Uscan in devscripts before 2
Uscan in devscripts before 2.13.9 allows remote attackers to execute arbitrary code via a crafted tarball.
OSV
CVE-2013-6888: Uscan in devscripts before 2
osv·2014-01-07·CVSS 7.5
CVE-2013-6888 [HIGH] CVE-2013-6888: Uscan in devscripts before 2
Uscan in devscripts before 2.13.9 allows remote attackers to execute arbitrary code via a crafted tarball.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-6888 devscripts: arbitrary code execution in uscan [fedora-20]
bugzilla·2014-01-06·CVSS 7.5
CVE-2013-6888 [HIGH] CVE-2013-6888 devscripts: arbitrary code execution in uscan [fedora-20]
CVE-2013-6888 devscripts: arbitrary code execution in uscan [fedora-20]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-20 tracking bug for devscr
Bugzilla
CVE-2013-6888 CVE-2013-7325 devscripts: arbitrary code execution in uscan
bugzilla·2014-01-06·CVSS 7.5
CVE-2013-6888 [HIGH] CVE-2013-6888 CVE-2013-7325 devscripts: arbitrary code execution in uscan
CVE-2013-6888 CVE-2013-7325 devscripts: arbitrary code execution in uscan
A flaw was reported in the uscan script of devscripts:
http://www.debian.org/security/2014/dsa-2836
From the bug report:
An attacker controlling a website from which uscan would attempt to download a source tarball could execute arbitrary code with the privileges of the user running uscan.
Discussion:
Created devscripts tracking bugs for this issue:
Affects: fedora-20 [bug 1048700]
---
From [1]: "[...] these problems have been fixed in version 2.13.9". F20+ ships devscripts-2.13.9. Closing bug.
[1] http://www.debian.org/security/2014/dsa-2836
---
While true, you closed with an incorrect status.
Also, a better reference is this note in the debian/changelog file (since we cannot know whether the advisory no
Bugzilla
CVE-2013-7085 devscripts: broken handling of filenames with whitespace in uscan
bugzilla·2013-12-12·CVSS 7.5
CVE-2013-7085 [HIGH] CVE-2013-7085 devscripts: broken handling of filenames with whitespace in uscan
CVE-2013-7085 devscripts: broken handling of filenames with whitespace in uscan
A flaw was reported in the uscan script of devscripts:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=732006
From the bug report:
If USCAN_EXCLUSION is enabled, uscan doesn't correctly handle filenames containing whitespace. This can be abused my malicious upstream to delete files of their choice.
devscripts is not included in Fedora 18 or 19. It looks to be part of rawhide/the upcoming Fedora 20.
Although some Debian stuff is bundled in the rpmdevtools package, uscan does not appear to be.
Discussion:
Created devscripts tracking bugs for this issue:
Affects: fedora-rawhide [bug 1040950]
---
CVE Request:
http://seclists.org/oss-sec/2013/q4/491
---
devscripts-2.13.9-1.fc20 has been pushed to the Fe
http://anonscm.debian.org/gitweb/?p=collab-maint/devscripts.git%3Ba=commitdiff%3Bh=02c6850d973e3e1246fde72edab27f03d63acc52http://marc.info/?l=oss-security&m=138900586911271&w=2http://secunia.com/advisories/56192http://secunia.com/advisories/56579http://www.debian.org/security/2014/dsa-2836http://www.securityfocus.com/bid/64656http://www.ubuntu.com/usn/USN-2084-1https://exchange.xforce.ibmcloud.com/vulnerabilities/90107http://anonscm.debian.org/gitweb/?p=collab-maint/devscripts.git%3Ba=commitdiff%3Bh=02c6850d973e3e1246fde72edab27f03d63acc52http://marc.info/?l=oss-security&m=138900586911271&w=2http://secunia.com/advisories/56192http://secunia.com/advisories/56579http://www.debian.org/security/2014/dsa-2836http://www.securityfocus.com/bid/64656http://www.ubuntu.com/usn/USN-2084-1https://exchange.xforce.ibmcloud.com/vulnerabilities/90107
2014-01-07
Published