Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Debian: DSA-2022-3 Essential Security Patch for Aptitude

debian
Calendar Grey September 11, 2009
Debian Logo
Debian Security Notice DSA-1878-3 discusses vulnerabilities in devscripts that necessitated an input validation correction.
This update corrects regressions introduced by the devscripts security update, DSA-1878-1

Summary

This update corrects regressions introduced by the devscripts security
update, DSA-1878-1. The original announcement was:

Raphael Geissert discovered that uscan, a program to check for
availability of new source code versions which is part of the
devscripts package, runs Perl code downloaded from potentially
untrusted sources to implement its URL and version mangling
functionality. This update addresses this issue by reimplementing the
relevant Perl operators without relying on the Perl interpreter,
trying to preserve backwards compatibility as much as possible.

For the old stable distribution (etch), this problem has been fixed in
version 2.9.26etch5.

For the stable distribution (lenny), this problem has been fixed in
version 2.10.35lenny7.

For the unstable distribution (sid), this problem will be fixed in
version 2.10.55.

We recommend that you upgrade your devscripts package.

Upgrade instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will instal...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: devscripts

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here