CVE-2018-13043: Code Injection
Last updated 25 August 2025
Other sources
scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a configuration that prevents unintended blessing.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-13043?
The severity of CVE-2018-13043 is critical with a severity value of 9.8.
What is the affected software for CVE-2018-13043?
The affected software for CVE-2018-13043 is Debian devscripts through 2.18.3 and Ubuntu devscripts versions 2.17.9ubuntu0.1, 2.17.12ubuntu1.1.
How can I fix CVE-2018-13043 on Ubuntu?
To fix CVE-2018-13043 on Ubuntu, update devscripts to version 2.17.9ubuntu0.1 or 2.17.12ubuntu1.1 depending on your Ubuntu version.
How can I fix CVE-2018-13043 on Debian?
To fix CVE-2018-13043 on Debian, update devscripts to version 2.19.5+deb10u1, 2.21.3+deb11u1, 2.23.4, or 2.23.6 depending on your Debian version.
Where can I find more information about CVE-2018-13043?
More information about CVE-2018-13043 can be found at the following references: [1] [2] [3].