Bugzilla – Bug 854878
VUL-0: CVE-2013-7050: devscripts: (uscan) command execution flaw
Last modified: 2015-04-01 11:55:51 UTC
OSS:11669 References: http://anonscm.debian.org/gitweb/?p=collab-maint/devscripts.git;a=commitdiff;h=91f05b5 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=731849 http://comments.gmane.org/gmane.comp.security.oss.general/11669
bugbot adjusting priority
CVE-2013-7050 was assigned to this issue.
cve.mitre.org: "The get_main_source_dir function in scripts/uscan.pl in devscripts before 2.13.8, when using USCAN_EXCLUSION, allows remote attackers to execute arbitrary commands via shell metacharacters in a directory name." The fix: http://anonscm.debian.org/gitweb/?p=collab-maint/devscripts.git;a=commitdiff;h=91f05b5
Fix together with bnc#855441.
not vulnerable in openSUSE>=13.1