REDHAT-BUG-1040266: High severity debian devscripts vulnerability
A flaw was reported in the uscan script of devscripts:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=731849
From that bug report:
"" The newfangled debian/copyright-driven repacking can be exploited by malicious upstream to execute arbitrary code. ""
The fix:
http://anonscm.debian.org/gitweb/?p=collab-maint/devscripts.git;a=commitdiff;h=91f05b5
devscripts is not included in Fedora 18 or 19. It looks to be part of rawhide/the upcoming Fedora 20.
Although some Debian stuff is bundled in the rpmdevtools package, uscan does not appear to be.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1040266?
The severity of REDHAT-BUG-1040266 is classified as high due to its potential to allow malicious exploitation.
How does REDHAT-BUG-1040266 affect the Debian devscripts package?
REDHAT-BUG-1040266 affects the uscan script in the devscripts package, allowing upstream exploitation through repacking.
How can I mitigate the risks associated with REDHAT-BUG-1040266?
To mitigate risks from REDHAT-BUG-1040266, it is recommended to update to the latest version of the devscripts package that contains the fix.
Is there a patch available for REDHAT-BUG-1040266?
Yes, a patch to address REDHAT-BUG-1040266 has been released and is included in the latest updates of the affected package.
What are the recommended steps to update the affected software for REDHAT-BUG-1040266?
To update the affected software for REDHAT-BUG-1040266, use your system's package manager to install the latest version of the devscripts package.