Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 12.04 LTS: USN-1593-1 Critical: Remote Code Exec in Devscripts

ubuntu
Calendar Grey October 2, 2012
Scroller Ubuntu
Multiple vulnerabilities addressed in Ubuntu devscripts across various versions. It's essential to keep your system current for optimal security.
Several security issues were fixed in devscripts.

Summary

Several security issues were fixed in devscripts.

Software Description:

- devscripts: scripts to make the life of a Debian Package maintainer easier

Details:

Raphael Geissert discovered that the debdiff.pl tool incorrectly handled

shell metacharacters. If a user or automated system were tricked into

processing a specially crafted filename, a remote attacher could possibly

execute arbitrary code. (CVE-2012-0212)

Raphael Geissert discovered that the dscverify tool incorrectly escaped

arguments to external commands. If a user or automated system were tricked

into processing specially crafted files, a remote attacher could possibly

execute arbitrary code. (CVE-2012-2240)

Raphael Geissert discovered that the dget tool incorrectly performed input

validation. If a user or automated system were tricked into processing

specially crafted files, a remote attacher could delete arbitrary files.

(CVE-2012-2241)

Raphael Geissert discovered that the dget tool incorrect...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  devscripts                      2.11.6ubuntu1.4

Ubuntu 11.10:
  devscripts                      2.11.1ubuntu3.2

Ubuntu 11.04:
  devscripts                      2.10.69ubuntu2.2

Ubuntu 10.04 LTS:
  devscripts                      2.10.61ubuntu5.3

In general, a standard system update will make all the necessary changes.

References

CVE-2012-0212, CVE-2012-2240, CVE-2012-2241, CVE-2012-2242,

CVE-2012-3500

Severity
critical
Lowest
Low
Medium
High
Critical

October 02, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.