First published: Tue Dec 03 2019(Updated: )
An issue exists in uscan in devscripts before 2.13.19, which could let a remote malicious user execute arbitrary code via a crafted tarball.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/devscripts | 2.19.5+deb10u1 2.21.3+deb11u1 2.23.4 2.23.6 | |
Debian devscripts | <2.13.19 | |
Debian GNU/Linux | =7.0 | |
Debian GNU/Linux | =8.0 | |
Debian GNU/Linux | =9.0 | |
Debian GNU/Linux | =10.0 | |
Debian GNU/Linux | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-7325 has a high severity due to the potential for remote code execution by malicious users.
To fix CVE-2013-7325, update the devscripts package to versions 2.19.5+deb10u1 or later.
Versions of devscripts before 2.13.19 are affected by CVE-2013-7325.
Yes, CVE-2013-7325 can be exploited by a remote malicious user through a crafted tarball.
Debian GNU/Linux versions prior to 2.13.19 in the devscripts package are vulnerable to CVE-2013-7325.