7.5
CVSSv2

CVE-2013-6888

Published: 07/01/2014 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Uscan in devscripts prior to 2.13.9 allows remote malicious users to execute arbitrary code via a crafted tarball.

Vulnerable Product Search on Vulmon Subscribe to Product

devscripts devel team devscripts 2.13.7

devscripts devel team devscripts 2.13.5

devscripts devel team devscripts

devscripts devel team devscripts 2.13.2

devscripts devel team devscripts 2.13.4

devscripts devel team devscripts 2.13.1

devscripts devel team devscripts 2.13.0

devscripts devel team devscripts 2.13.6

devscripts devel team devscripts 2.13.3

Vendor Advisories

Debian Bug report logs - #732006 uscan: broken handling of filenames with whitespace (CVE-2013-7085) Package: devscripts; Maintainer for devscripts is Devscripts Maintainers <devscripts@packagesdebianorg>; Source for devscripts is src:devscripts (PTS, buildd, popcon) Reported by: Jakub Wilk <jwilk@debianorg> Date: ...
devscripts could be made to run programs if it opened a specially crafted file ...
Several vulnerabilities have been discovered in uscan, a tool to scan upstream sites for new releases of packages, which is part of the devscripts package An attacker controlling a website from which uscan would attempt to download a source tarball could execute arbitrary code with the privileges of the user running uscan The Common Vulnerabiliti ...