First published: Tue Jan 07 2014(Updated: )
Uscan in devscripts before 2.13.9 allows remote attackers to execute arbitrary code via a crafted tarball.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Debian devscripts | <=2.13.8 | |
Debian devscripts | =2.13.0 | |
Debian devscripts | =2.13.1 | |
Debian devscripts | =2.13.2 | |
Debian devscripts | =2.13.3 | |
Debian devscripts | =2.13.4 | |
Debian devscripts | =2.13.5 | |
Debian devscripts | =2.13.6 | |
Debian devscripts | =2.13.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6888 is classified as a critical vulnerability that allows remote attackers to execute arbitrary code.
To fix CVE-2013-6888, upgrade to version 2.13.9 or later of the devscripts package.
CVE-2013-6888 affects devscripts versions prior to 2.13.9, including versions 2.13.0 to 2.13.8.
CVE-2013-6888 can allow remote attackers to execute arbitrary commands, potentially leading to full system compromise.
While there have been reports of this vulnerability, its current exploit status may vary and should be assessed with updated security information.