Debian: 2836-1: devscripts: arbitrary code execution

Posted by Ridcully on Jan 7, 2014 7:19 AM EDT
LinuxSecurity.com; By Benjamin D. Thomas
Mail this story
Print this story

Several vulnerabilities have been discovered in uscan, a tool to scan upstream sits for new releases of packages, which is part of the devscripts package. An attacker controlling a website from which uscan would attempt to download a source tarball could execute arbitrary code.

Full Story

  Nav
» Read more about: Story Type: News Story, Security; Groups: Debian, Developer

« Return to the newswire homepage

This topic does not have any threads posted yet!

You cannot post until you login.