First published: Wed Dec 11 2013(Updated: )
A flaw was reported in the uscan script of devscripts: <a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=731849">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=731849</a> From that bug report: "" The newfangled debian/copyright-driven repacking can be exploited by malicious upstream to execute arbitrary code. "" The fix: <a href="http://anonscm.debian.org/gitweb/?p=collab-maint/devscripts.git;a=commitdiff;h=91f05b5">http://anonscm.debian.org/gitweb/?p=collab-maint/devscripts.git;a=commitdiff;h=91f05b5</a> devscripts is not included in Fedora 18 or 19. It looks to be part of rawhide/the upcoming Fedora 20. Although some Debian stuff is bundled in the rpmdevtools package, uscan does not appear to be.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Devscripts Devel Team Devscripts | <=2.13.7 | |
Devscripts Devel Team Devscripts | =2.13.0 | |
Devscripts Devel Team Devscripts | =2.13.1 | |
Devscripts Devel Team Devscripts | =2.13.2 | |
Devscripts Devel Team Devscripts | =2.13.3 | |
Devscripts Devel Team Devscripts | =2.13.4 | |
Devscripts Devel Team Devscripts | =2.13.5 | |
Devscripts Devel Team Devscripts | =2.13.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.