9.3
CVSSv2

CVE-2012-0210

Published: 16/06/2012 Updated: 07/11/2023
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

debdiff.pl in devscripts 2.10.x prior to 2.10.69 and 2.11.x prior to 2.11.4 allows remote malicious users to obtain system information and execute arbitrary code via the file name in a (1) .dsc or (2) .changes file.

Vulnerable Product Search on Vulmon Subscribe to Product

devscripts devel team devscripts 2.10.28

devscripts devel team devscripts 2.10.59

devscripts devel team devscripts 2.10.62

devscripts devel team devscripts 2.10.65.1

devscripts devel team devscripts 2.10.24

devscripts devel team devscripts 2.10.48

devscripts devel team devscripts 2.10.16

devscripts devel team devscripts 2.10.61

devscripts devel team devscripts 2.10.54

devscripts devel team devscripts 2.10.56

devscripts devel team devscripts 2.10.43

devscripts devel team devscripts 2.10.7

devscripts devel team devscripts 2.10.8

devscripts devel team devscripts 2.10.64

devscripts devel team devscripts 2.10.46

devscripts devel team devscripts 2.10.55

devscripts devel team devscripts 2.10.50

devscripts devel team devscripts 2.10.34

devscripts devel team devscripts 2.10.49

devscripts devel team devscripts 2.10.36

devscripts devel team devscripts 2.10.12

devscripts devel team devscripts 2.10.1

devscripts devel team devscripts 2.10.18

devscripts devel team devscripts 2.10.33

devscripts devel team devscripts 2.10.27

devscripts devel team devscripts 2.10.35

devscripts devel team devscripts 2.10.13

devscripts devel team devscripts 2.10.25

devscripts devel team devscripts 2.10.68

devscripts devel team devscripts 2.10.20

devscripts devel team devscripts 2.10.53

devscripts devel team devscripts 2.10.17

devscripts devel team devscripts 2.10.11

devscripts devel team devscripts 2.10.52

devscripts devel team devscripts 2.10.22

devscripts devel team devscripts 2.10.67

devscripts devel team devscripts 2.10.31

devscripts devel team devscripts 2.10.15

devscripts devel team devscripts 2.10.44

devscripts devel team devscripts 2.10.10

devscripts devel team devscripts 2.10.66

devscripts devel team devscripts 2.10.47

devscripts devel team devscripts 2.10.29

devscripts devel team devscripts 2.10.30

devscripts devel team devscripts 2.10.42

devscripts devel team devscripts 2.10.57

devscripts devel team devscripts 2.10.19

devscripts devel team devscripts 2.10.6

devscripts devel team devscripts 2.10.23

devscripts devel team devscripts 2.10.21

devscripts devel team devscripts 2.10.41

devscripts devel team devscripts 2.10.39

devscripts devel team devscripts 2.10.9

devscripts devel team devscripts 2.10.51

devscripts devel team devscripts 2.10.60

devscripts devel team devscripts 2.10.26

devscripts devel team devscripts 2.10.3

devscripts devel team devscripts 2.10.32

devscripts devel team devscripts 2.10.14

devscripts devel team devscripts 2.10.58

devscripts devel team devscripts 2.10.0

devscripts devel team devscripts 2.10.38

devscripts devel team devscripts 2.10.40

devscripts devel team devscripts 2.10.45

devscripts devel team devscripts 2.10.63

devscripts devel team devscripts 2.10.18.1

devscripts devel team devscripts 2.11.2

devscripts devel team devscripts 2.11.1

devscripts devel team devscripts 2.11.3

devscripts devel team devscripts 2.11.0

Vendor Advisories

debdiff, a part of devscripts, could be made to run programs as your login if it opened a specially crafted file ...
Several vulnerabilities have been discovered in debdiff, a script used to compare two Debian packages, which is part of the devscripts package The following Common Vulnerabilities and Exposures project ids have been assigned to identify them: CVE-2012-0210: Paul Wise discovered that due to insufficient input sanitising when processing ds ...