Devscripts Devel Team

Devscripts

14 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Published 25.09.2017 21:29:00
  • Last modified 20.04.2025 01:37:25

scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands.

  • EPSS 0.83%
  • Published 06.09.2017 21:29:00
  • Last modified 20.04.2025 01:37:25

Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers to write to arbitrary files via a crafted symlink and crafted filename.

  • EPSS 0.77%
  • Published 05.02.2014 18:55:06
  • Last modified 11.04.2025 00:51:21

Directory traversal vulnerability in uupdate in devscripts 2.14.1 allows remote attackers to modify arbitrary files via a crafted .orig.tar file, related to a symlink.

  • EPSS 2.87%
  • Published 07.01.2014 17:04:52
  • Last modified 11.04.2025 00:51:21

Uscan in devscripts before 2.13.9 allows remote attackers to execute arbitrary code via a crafted tarball.

Exploit
  • EPSS 1.1%
  • Published 14.12.2013 17:21:47
  • Last modified 11.04.2025 00:51:21

Uscan in devscripts 2.13.5, when USCAN_EXCLUSION is enabled, allows remote attackers to delete arbitrary files via a whitespace character in a filename.

  • EPSS 0.84%
  • Published 13.12.2013 18:07:54
  • Last modified 11.04.2025 00:51:21

The get_main_source_dir function in scripts/uscan.pl in devscripts before 2.13.8, when using USCAN_EXCLUSION, allows remote attackers to execute arbitrary commands via shell metacharacters in a directory name.

  • EPSS 0.98%
  • Published 01.10.2012 00:55:01
  • Last modified 11.04.2025 00:51:21

scripts/dscverify.pl in devscripts before 2.12.3 allows remote attackers to execute arbitrary commands via unspecified vectors related to "arguments to external commands."

  • EPSS 0.56%
  • Published 01.10.2012 00:55:01
  • Last modified 11.04.2025 00:51:21

scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete arbitrary files via a crafted (1) .dsc or (2) .changes file, probably related to a NULL byte in a filename.

  • EPSS 0.64%
  • Published 01.10.2012 00:55:01
  • Last modified 11.04.2025 00:51:21

scripts/dget.pl in devscripts before 2.10.73 allows remote attackers to execute arbitrary commands via a crafted (1) .dsc or (2) .changes file, related to "arguments to external commands" that are not properly escaped, a different vulnerability than ...

  • EPSS 0.06%
  • Published 01.10.2012 00:55:01
  • Last modified 11.04.2025 00:51:21

scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools before 8.3, allows local users to modify arbitrary files via a symlink attack on the temporary (1) standard output or (2) standard error output file.