Devscripts Devel Team Devscripts vulnerabilities
16 known vulnerabilities affecting devscripts_devel_team/devscripts.
Total CVEs
16
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH5MEDIUM5LOW1
Vulnerabilities
Page 1 of 1
CVE-2013-7325P3HIGHCVSS 8.8≥ 0, < 2.13.92019-12-03
CVE-2013-7325 [HIGH] CVE-2013-7325: An issue exists in uscan in devscripts before 2
An issue exists in uscan in devscripts before 2.13.19, which could let a remote malicious user execute arbitrary code via a crafted tarball.
osv
CVE-2012-0212P3CRITICALCVSS 9.3v2.10.0v2.10.1+68 more2012-06-16
CVE-2012-0212 [CRITICAL] CWE-20 CVE-2012-0212: debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to e
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via shell metacharacters in the file name argument.
nvdosv
CVE-2012-0211P3CRITICALCVSS 9.3v2.10.0v2.10.1+68 more2012-06-16
CVE-2012-0211 [CRITICAL] CWE-20 CVE-2012-0211: debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to e
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via a crafted tarball file name in the top-level directory of an original (.orig) source tarball of a source package.
nvdosv
CVE-2018-13043P3CRITICALCVSS 9.8≥ 0, < 2.18.42018-07-01
CVE-2018-13043 [CRITICAL] CVE-2018-13043: scripts/grep-excuses
scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a configuration that prevents unintended blessing.
osv
CVE-2012-0210P3CRITICALCVSS 9.3v2.10.0v2.10.1+68 more2012-06-16
CVE-2012-0210 [CRITICAL] CWE-20 CVE-2012-0210: debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to o
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to obtain system information and execute arbitrary code via the file name in a (1) .dsc or (2) .changes file.
nvdosv
CVE-2012-2240P3HIGHCVSS 7.5≤ 2.12.2v2.7.0+86 more2012-10-01
CVE-2012-2240 [HIGH] CWE-20 CVE-2012-2240: scripts/dscverify.pl in devscripts before 2.12.3 allows remote attackers to execute arbitrary comman
scripts/dscverify.pl in devscripts before 2.12.3 allows remote attackers to execute arbitrary commands via unspecified vectors related to "arguments to external commands."
nvdosv
CVE-2009-2946P3CRITICALCVSS 9.3≥ 0, < 2.10.542009-09-04
CVE-2009-2946 [CRITICAL] CVE-2009-2946: Eval injection vulnerability in scripts/uscan
Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages.
osv
CVE-2015-5705P3HIGHCVSS 7.5≤ 2.15.62017-09-06
CVE-2015-5705 [HIGH] CWE-59 CVE-2015-5705: Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers to write to arb
Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers to write to arbitrary files via a crafted symlink and crafted filename.
nvdosv
CVE-2013-7050P3MEDIUMCVSS 6.8≤ 2.13.7v2.13.0+6 more2013-12-13
CVE-2013-7050 [MEDIUM] CWE-94 CVE-2013-7050: The get_main_source_dir function in scripts/uscan.pl in devscripts before 2.13.8, when using USCAN_E
The get_main_source_dir function in scripts/uscan.pl in devscripts before 2.13.8, when using USCAN_EXCLUSION, allows remote attackers to execute arbitrary commands via shell metacharacters in a directory name.
nvdosv
CVE-2013-6888P3HIGHCVSS 7.5≤ 2.13.8v2.13.0+7 more2014-01-07
CVE-2013-6888 [HIGH] CVE-2013-6888: Uscan in devscripts before 2.13.9 allows remote attackers to execute arbitrary code via a crafted ta
Uscan in devscripts before 2.13.9 allows remote attackers to execute arbitrary code via a crafted tarball.
nvdosv
CVE-2012-2242P3MEDIUMCVSS 6.8≤ 2.10.72v2.10.0+68 more2012-10-01
CVE-2012-2242 [MEDIUM] CVE-2012-2242: scripts/dget.pl in devscripts before 2.10.73 allows remote attackers to execute arbitrary commands v
scripts/dget.pl in devscripts before 2.10.73 allows remote attackers to execute arbitrary commands via a crafted (1) .dsc or (2) .changes file, related to "arguments to external commands" that are not properly escaped, a different vulnerability than CVE-2012-2240.
nvdosv
CVE-2015-5704P3HIGHCVSS 7.8≤ 2.15.62017-09-25
CVE-2015-5704 [HIGH] CWE-77 CVE-2015-5704: scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell co
scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands.
nvdosv
CVE-2014-1833P4MEDIUMCVSS 5.0v2.14.12014-02-05
CVE-2014-1833 [MEDIUM] CWE-22 CVE-2014-1833: Directory traversal vulnerability in uupdate in devscripts 2.14.1 allows remote attackers to modify
Directory traversal vulnerability in uupdate in devscripts 2.14.1 allows remote attackers to modify arbitrary files via a crafted .orig.tar file, related to a symlink.
nvdosv
CVE-2013-7085P4MEDIUMCVSS 5.8v2.13.52013-12-14
CVE-2013-7085 [MEDIUM] CWE-20 CVE-2013-7085: Uscan in devscripts 2.13.5, when USCAN_EXCLUSION is enabled, allows remote attackers to delete arbit
Uscan in devscripts 2.13.5, when USCAN_EXCLUSION is enabled, allows remote attackers to delete arbitrary files via a whitespace character in a filename.
nvdosv
CVE-2012-2241P4MEDIUMCVSS 5.0≤ 2.12.2v2.7.0+86 more2012-10-01
CVE-2012-2241 [MEDIUM] CWE-20 CVE-2012-2241: scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete arbitrary files via a
scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete arbitrary files via a crafted (1) .dsc or (2) .changes file, probably related to a NULL byte in a filename.
nvdosv
CVE-2012-3500P4LOWCVSS 1.2≤ 2.12.1v2.12.02012-10-01
CVE-2012-3500 [LOW] CWE-362 CVE-2012-3500: scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools before 8.3, allows lo
scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools before 8.3, allows local users to modify arbitrary files via a symlink attack on the temporary (1) standard output or (2) standard error output file.
nvdosv