REDHAT-BUG-1249645: Medium severity debian devscripts vulnerability
In scripts/licensecheck.pl, there is code segment vulnerable to argument injection.
my $mime = file --brief --mime --dereference $file;
Upstream patch: https://anonscm.debian.org/cgit/collab-maint/devscripts.git/commit/?id=d8f8fa1d8e4151fa62997cb74403f97ab0d7e1a2
CVE assignment: http://www.openwall.com/lists/oss-security/2015/08/01/7
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1249645?
The severity of REDHAT-BUG-1249645 is considered moderate due to the potential for argument injection.
How do I fix REDHAT-BUG-1249645?
To fix REDHAT-BUG-1249645, apply the upstream patch provided in the Debian devscripts repository.
What software is affected by REDHAT-BUG-1249645?
REDHAT-BUG-1249645 affects the Debian devscripts package.
When was REDHAT-BUG-1249645 discovered?
The vulnerability represented by REDHAT-BUG-1249645 was discovered in 2015.
What is the nature of the vulnerability in REDHAT-BUG-1249645?
The nature of the vulnerability in REDHAT-BUG-1249645 involves argument injection in the licensecheck.pl script.