CVE-2013-6888: High severity Devscripts Devel Team Devscripts vulnerability
Published Jan 7, 2014
·Updated
Uscan in devscripts before 2.13.9 allows remote attackers to execute arbitrary code via a crafted tarball.
Affected Software
9 affected components
Devscripts Devel Team Devscripts<=2.13.8
Devscripts Devel Team Devscripts=2.13.0
Devscripts Devel Team Devscripts=2.13.1
Devscripts Devel Team Devscripts=2.13.2
Devscripts Devel Team Devscripts=2.13.3
Devscripts Devel Team Devscripts=2.13.4
Devscripts Devel Team Devscripts=2.13.5
Devscripts Devel Team Devscripts=2.13.6
Devscripts Devel Team Devscripts=2.13.7
Event History
Jan 7, 2014
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:04 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6888?
CVE-2013-6888 is classified as a critical vulnerability that allows remote attackers to execute arbitrary code.
2
How do I fix CVE-2013-6888?
To fix CVE-2013-6888, upgrade to version 2.13.9 or later of the devscripts package.
3
Which versions of devscripts are affected by CVE-2013-6888?
CVE-2013-6888 affects devscripts versions prior to 2.13.9, including versions 2.13.0 to 2.13.8.
4
What impact does CVE-2013-6888 have on affected systems?
CVE-2013-6888 can allow remote attackers to execute arbitrary commands, potentially leading to full system compromise.
5
Is CVE-2013-6888 being actively exploited?
While there have been reports of this vulnerability, its current exploit status may vary and should be assessed with updated security information.