debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via a crafted tarball file name in the top-level directory of an original (.orig) source tarball of a source package.

Project Subscriptions

Vendors Products
Devscripts Devel Team Subscribe
Devscripts Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-2409-1 devscripts security update
Ubuntu USN Ubuntu USN USN-1366-1 devscripts vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: debian

Published:

Updated: 2024-08-06T18:16:19.612Z

Reserved: 2011-12-14T00:00:00.000Z

Link: CVE-2012-0211

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2012-06-16T00:55:05.920

Modified: 2026-04-29T01:13:23.040

Link: CVE-2012-0211

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses