
CVE-2015-5704
https://notcve.org/view.php?id=CVE-2015-5704
25 Sep 2017 — scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands. scripts/licensecheck.pl en devscripts en versiones anteriores a la 2.15.7 permite que los usuarios locales ejecuten comandos shell arbitrarios. • http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163705.html • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVE-2015-5705
https://notcve.org/view.php?id=CVE-2015-5705
06 Sep 2017 — Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers to write to arbitrary files via a crafted symlink and crafted filename. Una vulnerabilidad de inyección de argumentos en versiones anteriores a la 2.15.7 de devscripts permite a atacantes escribir en archivos arbitrarios utilizando un enlace simbólico y un nombre de archivo manipulados. • http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163705.html • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVE-2014-1833 – Ubuntu Security Notice USN-2649-1
https://notcve.org/view.php?id=CVE-2014-1833
05 Feb 2014 — Directory traversal vulnerability in uupdate in devscripts 2.14.1 allows remote attackers to modify arbitrary files via a crafted .orig.tar file, related to a symlink. Vulnerabilidad de salto de directorio en uupdate en Devscripts 2.14.1 permite a atacantes remotos modificar archivos arbitrarios a través de un archivo .orig.tar manipulado, relacionado a un symlink. It was discovered that the uupdate tool incorrectly handled symlinks. If a user or automated system were tricked into processing specially craft... • http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737160 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2013-6888 – Debian Security Advisory 2836-1
https://notcve.org/view.php?id=CVE-2013-6888
06 Jan 2014 — Uscan in devscripts before 2.13.9 allows remote attackers to execute arbitrary code via a crafted tarball. Uscan en devscripts anteriores a 2.13.9 permite a atacantes remotos ejecutar código arbitrario a través de un tarball manipulado. Several vulnerabilities have been discovered in uscan, a tool to scan upstream sits for new releases of packages, which is part of the devscripts package. An attacker controlling a website from which uscan would attempt to download a source tarball could execute arbitrary co... • http://anonscm.debian.org/gitweb/?p=collab-maint/devscripts.git%3Ba=commitdiff%3Bh=02c6850d973e3e1246fde72edab27f03d63acc52 •

CVE-2013-7085
https://notcve.org/view.php?id=CVE-2013-7085
14 Dec 2013 — Uscan in devscripts 2.13.5, when USCAN_EXCLUSION is enabled, allows remote attackers to delete arbitrary files via a whitespace character in a filename. Uscan en devscripts 2.13.5, cuando se activa USCAN_EXCLUSION, permite a atacantes remotos eliminar archivos arbitrarios a través de un caracter de espacio en blanco en un nombre de archivo. • http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=732006 • CWE-20: Improper Input Validation •

CVE-2013-7050
https://notcve.org/view.php?id=CVE-2013-7050
13 Dec 2013 — The get_main_source_dir function in scripts/uscan.pl in devscripts before 2.13.8, when using USCAN_EXCLUSION, allows remote attackers to execute arbitrary commands via shell metacharacters in a directory name. La función get_main_source_dir en scripts/uscan.pl en devscripts anterior a 2.13.8, al utilizar USCAN_EXCLUSION, permite a atacantes remotos ejecutar comandos arbitrarios mediante metacaracteres de shell en un nombre de directorio. • http://anonscm.debian.org/gitweb/?p=collab-maint/devscripts.git%3Ba=commitdiff%3Bh=91f05b5 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2012-3500
https://notcve.org/view.php?id=CVE-2012-3500
01 Oct 2012 — scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools before 8.3, allows local users to modify arbitrary files via a symlink attack on the temporary (1) standard output or (2) standard error output file. scripts/annotate-output.sh en devscripts anteriores a v2.12.2, como el usado en rpmdevtools anteriores a v8.3, permite a usuarios locales modificar ficheros a través de un ataque de enlaces simbólicos sobre los ficheros temporales de (1) salida estándar o (2) salida estándar de erro... • http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git%3Ba=commit%3Bh=4d23a5e6c90f7a37b0972b30f5d31dce97a93eb0 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •

CVE-2012-2240
https://notcve.org/view.php?id=CVE-2012-2240
01 Oct 2012 — scripts/dscverify.pl in devscripts before 2.12.3 allows remote attackers to execute arbitrary commands via unspecified vectors related to "arguments to external commands." scripts/dscverify.pl en devscripts anterior a v2.12.3 permite a atacantes remotos ejecutar comandos arbitarios mediante vectores no especificados relacionados con "argumentos a comandos externos" • http://secunia.com/advisories/50600 • CWE-20: Improper Input Validation •

CVE-2012-2241
https://notcve.org/view.php?id=CVE-2012-2241
01 Oct 2012 — scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete arbitrary files via a crafted (1) .dsc or (2) .changes file, probably related to a NULL byte in a filename. scripts/dget.pl en devscripts anterior a v2.12.3 permite a atacantes remotos borrar ficheros arbitrarios mediante un fichero (1) .dsc o (2) .changes manipulado, probablemente relacionado con un byte NULL en un nombre de fichero. • http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git%3Ba=commitdiff%3Bh=0fd15bdec07b085f9ef438dacd18e159ac60b810 • CWE-20: Improper Input Validation •

CVE-2012-2242
https://notcve.org/view.php?id=CVE-2012-2242
01 Oct 2012 — scripts/dget.pl in devscripts before 2.10.73 allows remote attackers to execute arbitrary commands via a crafted (1) .dsc or (2) .changes file, related to "arguments to external commands" that are not properly escaped, a different vulnerability than CVE-2012-2240. scripts/dget.pl en devscripts anterior a v2.10.73 permite a atacantes remotos ejecutar comandos arbitrarios mediante un fichero (1) .dsc o (2) .changes manipulado, relacionado con "argumentos a comandos externos" que no son escapados correctamente... • http://secunia.com/advisories/50600 • CWE-20: Improper Input Validation •