Show filters
16 Total Results
Displaying 11-16 of 16
Sort by:
Attacker Value
Unknown
CVE-2012-3500
Disclosure Date: October 01, 2012 (last updated October 05, 2023)
scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools before 8.3, allows local users to modify arbitrary files via a symlink attack on the temporary (1) standard output or (2) standard error output file.
0
Attacker Value
Unknown
CVE-2012-2241
Disclosure Date: October 01, 2012 (last updated October 05, 2023)
scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete arbitrary files via a crafted (1) .dsc or (2) .changes file, probably related to a NULL byte in a filename.
0
Attacker Value
Unknown
CVE-2012-0212
Disclosure Date: June 16, 2012 (last updated October 04, 2023)
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via shell metacharacters in the file name argument.
0
Attacker Value
Unknown
CVE-2012-0210
Disclosure Date: June 16, 2012 (last updated October 04, 2023)
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to obtain system information and execute arbitrary code via the file name in a (1) .dsc or (2) .changes file.
0
Attacker Value
Unknown
CVE-2012-0211
Disclosure Date: June 16, 2012 (last updated October 04, 2023)
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via a crafted tarball file name in the top-level directory of an original (.orig) source tarball of a source package.
0
Attacker Value
Unknown
CVE-2009-2946
Disclosure Date: September 04, 2009 (last updated October 04, 2023)
Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages.
0