7.5
CVSSv2

CVE-2013-6888

Published: 07/01/2014 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Uscan in devscripts prior to 2.13.9 allows remote malicious users to execute arbitrary code via a crafted tarball.

Vulnerable Product Search on Vulmon Subscribe to Product

devscripts devel team devscripts 2.13.7

devscripts devel team devscripts 2.13.5

devscripts devel team devscripts

devscripts devel team devscripts 2.13.2

devscripts devel team devscripts 2.13.4

devscripts devel team devscripts 2.13.1

devscripts devel team devscripts 2.13.0

devscripts devel team devscripts 2.13.6

devscripts devel team devscripts 2.13.3

Vendor Advisories

devscripts could be made to run programs if it opened a specially crafted file ...
Debian Bug report logs - #732006 uscan: broken handling of filenames with whitespace (CVE-2013-7085) Package: devscripts; Maintainer for devscripts is Devscripts Maintainers <devscripts@packagesdebianorg>; Source for devscripts is src:devscripts (PTS, buildd, popcon) Reported by: Jakub Wilk <jwilk@debianorg> Date: ...
Several vulnerabilities have been discovered in uscan, a tool to scan upstream sites for new releases of packages, which is part of the devscripts package An attacker controlling a website from which uscan would attempt to download a source tarball could execute arbitrary code with the privileges of the user running uscan The Common Vulnerabiliti ...