Show filters
16 Total Results
Displaying 11-16 of 16
Sort by:
Attacker Value
Unknown

CVE-2012-3500

Disclosure Date: October 01, 2012 (last updated October 05, 2023)
scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools before 8.3, allows local users to modify arbitrary files via a symlink attack on the temporary (1) standard output or (2) standard error output file.
0
Attacker Value
Unknown

CVE-2012-2241

Disclosure Date: October 01, 2012 (last updated October 05, 2023)
scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete arbitrary files via a crafted (1) .dsc or (2) .changes file, probably related to a NULL byte in a filename.
0
Attacker Value
Unknown

CVE-2012-0212

Disclosure Date: June 16, 2012 (last updated October 04, 2023)
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via shell metacharacters in the file name argument.
0
Attacker Value
Unknown

CVE-2012-0210

Disclosure Date: June 16, 2012 (last updated October 04, 2023)
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to obtain system information and execute arbitrary code via the file name in a (1) .dsc or (2) .changes file.
0
Attacker Value
Unknown

CVE-2012-0211

Disclosure Date: June 16, 2012 (last updated October 04, 2023)
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via a crafted tarball file name in the top-level directory of an original (.orig) source tarball of a source package.
0
Attacker Value
Unknown

CVE-2009-2946

Disclosure Date: September 04, 2009 (last updated October 04, 2023)
Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages.
0