Skip to main content

Vendor archive

devscripts_devel_team CVEs

Beta · best-effort

14 CVEs tagged to vendor devscripts_devel_team4 Critical, 4 High, 5 Medium, 1 Low, 0 Unrated.

CVE-2014-1833

Published Feb 5, 2014

Directory traversal vulnerability in uupdate in devscripts 2.14.1 allows remote attackers to modify arbitrary files via a crafted .orig.tar file, related to a symlink.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7085

Published Dec 14, 2013

Uscan in devscripts 2.13.5, when USCAN_EXCLUSION is enabled, allows remote attackers to delete arbitrary files via a whitespace character in a filename.

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7050

Published Dec 13, 2013

The get_main_source_dir function in scripts/uscan.pl in devscripts before 2.13.8, when using USCAN_EXCLUSION, allows remote attackers to execute arbitrary commands via shell metac…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2242

Published Oct 1, 2012

scripts/dget.pl in devscripts before 2.10.73 allows remote attackers to execute arbitrary commands via a crafted (1) .dsc or (2) .changes file, related to "arguments to external c…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2241

Published Oct 1, 2012

scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete arbitrary files via a crafted (1) .dsc or (2) .changes file, probably related to a NULL byte in a fil…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2240

Published Oct 1, 2012

scripts/dscverify.pl in devscripts before 2.12.3 allows remote attackers to execute arbitrary commands via unspecified vectors related to "arguments to external commands."

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-0212

Published Jun 16, 2012

debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via shell metacharacters in the file name argument.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-0211

Published Jun 16, 2012

debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via a crafted tarball file name in the top-level director…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-0210

Published Jun 16, 2012

debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to obtain system information and execute arbitrary code via the file name in a (1)…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2946

Published Sep 4, 2009

Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1