CVE-2013-7325: High severity Debian devscripts vulnerability
Published Dec 3, 2019
·Updated
An issue exists in uscan in devscripts before 2.13.19, which could let a remote malicious user execute arbitrary code via a crafted tarball.
Affected Software
7 affected componentsFixes available
Debian devscripts<2.13.19
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
debian/devscripts
2.21.3+deb11u12.23.4+deb12u22.25.15+deb13u12.26.5
Event History
Dec 3, 2019
CVE Published
via MITRE·10:23 PM
Data Sourced
via MITRE·10:23 PM
Description
Feb 18, 2026
Data Sourced
via Debian·05:55 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-7325?
CVE-2013-7325 has a high severity due to the potential for remote code execution by malicious users.
2
How do I fix CVE-2013-7325?
To fix CVE-2013-7325, update the devscripts package to versions 2.19.5+deb10u1 or later.
3
Which versions of devscripts are affected by CVE-2013-7325?
Versions of devscripts before 2.13.19 are affected by CVE-2013-7325.
4
Can CVE-2013-7325 be exploited remotely?
Yes, CVE-2013-7325 can be exploited by a remote malicious user through a crafted tarball.
5
What platforms are vulnerable to CVE-2013-7325?
Debian GNU/Linux versions prior to 2.13.19 in the devscripts package are vulnerable to CVE-2013-7325.