CVE-2015-5704
- EPSS 0.05%
- Veröffentlicht 25.09.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands.
CVE-2015-5705
- EPSS 0.83%
- Veröffentlicht 06.09.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers to write to arbitrary files via a crafted symlink and crafted filename.
- EPSS 0.77%
- Veröffentlicht 05.02.2014 18:55:06
- Zuletzt bearbeitet 11.04.2025 00:51:21
Directory traversal vulnerability in uupdate in devscripts 2.14.1 allows remote attackers to modify arbitrary files via a crafted .orig.tar file, related to a symlink.
CVE-2013-6888
- EPSS 2.87%
- Veröffentlicht 07.01.2014 17:04:52
- Zuletzt bearbeitet 11.04.2025 00:51:21
Uscan in devscripts before 2.13.9 allows remote attackers to execute arbitrary code via a crafted tarball.
CVE-2013-7085
- EPSS 1.1%
- Veröffentlicht 14.12.2013 17:21:47
- Zuletzt bearbeitet 11.04.2025 00:51:21
Uscan in devscripts 2.13.5, when USCAN_EXCLUSION is enabled, allows remote attackers to delete arbitrary files via a whitespace character in a filename.
CVE-2013-7050
- EPSS 0.84%
- Veröffentlicht 13.12.2013 18:07:54
- Zuletzt bearbeitet 11.04.2025 00:51:21
The get_main_source_dir function in scripts/uscan.pl in devscripts before 2.13.8, when using USCAN_EXCLUSION, allows remote attackers to execute arbitrary commands via shell metacharacters in a directory name.
CVE-2012-2240
- EPSS 0.98%
- Veröffentlicht 01.10.2012 00:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
scripts/dscverify.pl in devscripts before 2.12.3 allows remote attackers to execute arbitrary commands via unspecified vectors related to "arguments to external commands."
- EPSS 0.56%
- Veröffentlicht 01.10.2012 00:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete arbitrary files via a crafted (1) .dsc or (2) .changes file, probably related to a NULL byte in a filename.
CVE-2012-2242
- EPSS 0.64%
- Veröffentlicht 01.10.2012 00:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
scripts/dget.pl in devscripts before 2.10.73 allows remote attackers to execute arbitrary commands via a crafted (1) .dsc or (2) .changes file, related to "arguments to external commands" that are not properly escaped, a different vulnerability than ...
CVE-2012-3500
- EPSS 0.06%
- Veröffentlicht 01.10.2012 00:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools before 8.3, allows local users to modify arbitrary files via a symlink attack on the temporary (1) standard output or (2) standard error output file.