9.8
CVSSv3

CVE-2018-13043

Published: 01/07/2018 Updated: 19/08/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

scripts/grep-excuses.pl in Debian devscripts up to and including 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a configuration that prevents unintended blessing.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian devscripts

canonical ubuntu linux 17.10

canonical ubuntu linux 18.04

Vendor Advisories

Debian Bug report logs - #902409 devscripts: CVE-2018-13043 - grep-excuses uses YAML::Syck in a unsafe way Package: devscripts; Maintainer for devscripts is Devscripts Maintainers <devscripts@packagesdebianorg>; Source for devscripts is src:devscripts (PTS, buildd, popcon) Reported by: Ansgar Burchardt <ansgar@debianor ...
devscripts could be made to run arbitrary code if it received a specially crafted YAML file ...