Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
* bsc#861514 Cross-References: * CVE-2014-1833 . # Security update for devscripts Announcement ID: SUSE-SU-2024:2621-1 Rating: moderate References: * bsc#861514 Cross-References: * CVE-2014-1833 CVSS scores: * CVE-2014-1833 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for devscripts fixes the following issues: * CVE-2014-1833: Fixed symlink directory traversal in uupdate (bsc#861514) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-2621=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (noarch) * checkbashisms-2.12.6-5.3.1 ## References: * https://www.suse.com/security/cve/CVE-2014-1833.html * https://bugzilla.suse.com/show_bug.cgi?id=861514 . A security enhancement for devscripts resolves a moderate-risk concern involving symlink directory traversal.. Update For Devscripts,SUSE Security Advisory,Moderate Severity Fix,SUSE Linux Enterprise Advisory. . LinuxSecurity.com Team
Update to devscripts-2.18.4, see for details.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-1ce5098a2d 2018-09-21 05:19:39.106935 --------------------------------------------------------------------------------Name : devscripts Product : Fedora 29 Version : 2.18.4 Release : 1.fc29 URL : https://packages.debian.org/sid/devscripts Summary : Scripts for Debian Package maintainers Description : Scripts to make the life of a Debian Package maintainer easier. --------------------------------------------------------------------------------Update Information: Update to devscripts-2.18.4, see for details. --------------------------------------------------------------------------------References: [ 1 ] Bug #1597581 - CVE-2018-13043 devscripts: grep-excuses uses YAML:Syck unsafely [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1597581 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-1ce5098a2d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
devscripts could be made to run arbitrary code if it received a specially crafted YAML file.. =========================================================================Ubuntu Security Notice USN-3704-1 July 05, 2018 devscripts vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 17.10 Summary: devscripts could be made to run arbitrary code if it received a specially crafted YAML file. Software Description: - devscripts: scripts to make the life of a Debian Package maintainer easier Details: It was discovered that devscripts incorrectly handled certain YAML files. An attacker could possibly use this to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: devscripts 2.17.12ubuntu1.1 Ubuntu 17.10: devscripts 2.17.9ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3704-1 CVE-2018-13043 Package Information: https://launchpad.net/ubuntu/+source/devscripts/2.17.12ubuntu1.1 https://launchpad.net/ubuntu/+source/devscripts/2.17.9ubuntu0.1 . Fedora Security Advisory FSA-2023-456 informs users about a vulnerability in the pkgen package that may permit unauthorized data access through SQL queries.. arbitrary Code Execution, devscripts, Ubuntu 17.10, Ubuntu 18.04, security Advisory. . LinuxSecurity.com Team
Update to version 2.15.8, see for details. Fixes CVE-2015-5705. Update to version 2.15.7, see for details. This update fixes licensecheck refusing to parse some text files such as C++ source files. Update to [More...]. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-12716 2015-08-04 03:15:15 -------------------------------------------------------------------------------- Name : devscripts Product : Fedora 21 Version : 2.15.8 Release : 1.fc21 URL : https://packages.debian.org/sid/devscripts Summary : Scripts for Debian Package maintainersDescription : Scripts to make the life of a Debian Package maintainer easier. -------------------------------------------------------------------------------- Update Information: Update to version 2.15.8, see for details. Fixes CVE-2015-5705. Update to version 2.15.7, see for details. This update fixes licensecheck refusing to parse some text files such as C++ source files. Update to version 2.15.6, see for details. Update to version 2.15.6, see for details. This update fixes licensecheck refusing to parse some text files such as C++ source files. Update to version 2.15.6, see for details. Update to version 2.15.6, see for details. Update to version 2.15.7, see for details. This update fixes licensecheck refusing to parse some text files such as C++ source files. Update to version 2.15.6, see for details. Update to version 2.15.6, see for details. This update fixes licensecheck refusing to parse some text files such as C++ source files. Update to version 2.15.6, see for details. Update to version 2.15.6, see for details. -------------------------------------------------------------------------------- ChangeLog: * Mon Aug 3 2015 Sandro Mani - 2.15.8-1 - Update to 2.15.8 * Sat Aug 1 2015 Sandro Mani - 2.15.7-1 - Update to 2.15.7 * Sat Aug 1 2015 Sandro Mani - 2.15.6-2 - Fix licensecheck incorrectly detecting mime strings such astext/x-c++ as a binary file (#1249227) * Wed Jul 29 2015 Sandro Mani - 2.15.6-1 - Update to 2.15.6 * Thu Jul 9 2015 Sandro Mani - 2.15.5-6 - Make licensecheck print a warning when scanned file is not a text file (#1240914) * Fri Jun 26 2015 Sandro Mani - 2.15.5-5 - Create symlinks like the debian package does (#1236122) * Wed Jun 17 2015 Ralf Corsépius - 2.15.5-4 - Add: "Requires: perl(:MODULE_COMPAT_...)" * Wed Jun 17 2015 Ralf Corsépius - 2.15.5-3 - Fix FTBFS. - Eliminate libvfork, PKGLIBDIR (Abandoned upstream). - Rework perl-BRs. - Reflect upstream installing perl-modules into perl_vendordir. - Reflect upstream installing bash-completion into /usr/share/bash-completion. - BR: /usr/bin/dpkg-buildflags, /usr/bin/dpkg-vendor, /usr/bin/dpkg-parsechangelog. - BR: pkgconfig(bash-completion). - Remove archpath, whodepends's man-pages. - Rebase patches. * Wed Jun 17 2015 Fedora Release Engineering - 2.15.5-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild * Fri Jun 12 2015 Sandro Mani - 2.15.5-1 - Update to 2.15.5 * Tue Apr 28 2015 Sandro Mani - 2.15.4-1 - Update to 2.15.4 * Mon Apr 13 2015 Sandro Mani - 2.15.3-1 - Update to 2.15.3 * Fri Apr 3 2015 Sandro Mani - 2.15.2-1 - Update to 2.15.2 - Don't install whodepends (#1185511) * Fri Jan 2 2015 Sandro Mani - 2.15.1-1 - Update to 2.15.1 * Thu Dec 4 2014 Sandro Mani - 2.14.11-1 - Update to 2.14.11 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1249635 - CVE-2015-5704 devscripts: arbitrary shell command injection https://bugzilla.redhat.com/show_bug.cgi?id=1249635 [ 2 ] Bug #1249645 - CVE-2015-5705 devscripts: argument injection vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=1249645 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update devscripts' at the command line. For more information, refer to "Managing Softwarewith yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Update to version 2.15.8, see for details. Fixes CVE-2015-5705. Update to version 2.15.7, see for details. This update fixes licensecheck refusing to parse some text files such as C++ source files. Update to [More...]. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-12699 2015-08-04 03:14:24 -------------------------------------------------------------------------------- Name : devscripts Product : Fedora 22 Version : 2.15.8 Release : 1.fc22 URL : https://packages.debian.org/sid/devscripts Summary : Scripts for Debian Package maintainersDescription : Scripts to make the life of a Debian Package maintainer easier. -------------------------------------------------------------------------------- Update Information: Update to version 2.15.8, see for details. Fixes CVE-2015-5705. Update to version 2.15.7, see for details. This update fixes licensecheck refusing to parse some text files such as C++ source files. Update to version 2.15.6, see for details. Update to version 2.15.6, see for details. This update fixes licensecheck refusing to parse some text files such as C++ source files. Update to version 2.15.6, see for details. Update to version 2.15.6, see for details. Update to version 2.15.7, see for details. This update fixes licensecheck refusing to parse some text files such as C++ source files. Update to version 2.15.6, see for details. Update to version 2.15.6, see for details. This update fixes licensecheck refusing to parse some text files such as C++ source files. Update to version 2.15.6, see for details. Update to version 2.15.6, see for details. -------------------------------------------------------------------------------- ChangeLog: * Mon Aug 3 2015 Sandro Mani - 2.15.8-1 - Update to 2.15.8 * Sat Aug 1 2015 Sandro Mani - 2.15.7-1 - Update to 2.15.7 * Sat Aug 1 2015 Sandro Mani - 2.15.6-2 - Fix licensecheck incorrectly detecting mime strings such astext/x-c++ as a binary file (#1249227) * Wed Jul 29 2015 Sandro Mani - 2.15.6-1 - Update to 2.15.6 * Thu Jul 9 2015 Sandro Mani - 2.15.5-6 - Make licensecheck print a warning when scanned file is not a text file (#1240914) * Fri Jun 26 2015 Sandro Mani - 2.15.5-5 - Create symlinks like the debian package does (#1236122) * Wed Jun 17 2015 Ralf Corsépius - 2.15.5-4 - Add: "Requires: perl(:MODULE_COMPAT_...)" * Wed Jun 17 2015 Ralf Corsépius - 2.15.5-3 - Fix FTBFS. - Eliminate libvfork, PKGLIBDIR (Abandoned upstream). - Rework perl-BRs. - Reflect upstream installing perl-modules into perl_vendordir. - Reflect upstream installing bash-completion into /usr/share/bash-completion. - BR: /usr/bin/dpkg-buildflags, /usr/bin/dpkg-vendor, /usr/bin/dpkg-parsechangelog. - BR: pkgconfig(bash-completion). - Remove archpath, whodepends's man-pages. - Rebase patches. * Wed Jun 17 2015 Fedora Release Engineering - 2.15.5-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild * Fri Jun 12 2015 Sandro Mani - 2.15.5-1 - Update to 2.15.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1249635 - CVE-2015-5704 devscripts: arbitrary shell command injection https://bugzilla.redhat.com/show_bug.cgi?id=1249635 [ 2 ] Bug #1249645 - CVE-2015-5705 devscripts: argument injection vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=1249645 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update devscripts' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailinglist
devscripts could be made to overwrite files.. =========================================================================Ubuntu Security Notice USN-2649-1 June 16, 2015 devscripts vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: devscripts could be made to overwrite files. Software Description: - devscripts: scripts to make the life of a Debian Package maintainer easier Details: It was discovered that the uupdate tool incorrectly handled symlinks. If a user or automated system were tricked into processing specially crafted files, a remote attacker could possibly replace arbitrary files, leading to a privilege escalation. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.10: devscripts 2.14.6ubuntu0.1 Ubuntu 14.04 LTS: devscripts 2.14.1ubuntu0.1 Ubuntu 12.04 LTS: devscripts 2.11.6ubuntu1.7 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2649-1 CVE-2014-1833 Package Information: https://launchpad.net/ubuntu/+source/devscripts/2.14.6ubuntu0.1 https://launchpad.net/ubuntu/+source/devscripts/2.14.1ubuntu0.1 https://launchpad.net/ubuntu/+source/devscripts/2.11.6ubuntu1.7 . A vulnerability present in devscripts for Ubuntu may enable remote malicious actors to replace files, potentially resulting in elevated privileges.. Ubuntu Devscripts Update, File Overwrite Risk, Privilege Escalation Prevention. . Severity: Important. LinuxSecurity.com Team
devscripts could be made to run programs if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-2084-1 January 21, 2014 devscripts vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 13.10 - Ubuntu 13.04 - Ubuntu 12.10 - Ubuntu 12.04 LTS - Ubuntu 10.04 LTS Summary: devscripts could be made to run programs if it opened a specially crafted file. Software Description: - devscripts: scripts to make the life of a Debian Package maintainer easier Details: It was discovered that the uscan tool incorrectly repacked archive files. If a user or automated system were tricked into processing specially crafted files, a remote attacker could possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 13.10: devscripts 2.13.4ubuntu0.1 Ubuntu 13.04: devscripts 2.13.1ubuntu0.1 Ubuntu 12.10: devscripts 2.12.4ubuntu0.1 Ubuntu 12.04 LTS: devscripts 2.11.6ubuntu1.6 Ubuntu 10.04 LTS: devscripts 2.10.61ubuntu5.6 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2084-1 CVE-2013-6888 Package Information: https://launchpad.net/ubuntu/+source/devscripts/2.13.4ubuntu0.1 https://launchpad.net/ubuntu/+source/devscripts/2.13.1ubuntu0.1 https://launchpad.net/ubuntu/+source/devscripts/2.12.4ubuntu0.1 https://launchpad.net/ubuntu/+source/devscripts/2.11.6ubuntu1.6 https://launchpad.net/ubuntu/+source/devscripts/2.10.61ubuntu5.6 . Debian Security Advisory DSA-4852-1 notifies users of a critical vulnerability in the apache2 package that may risk unauthorized access to sensitivedata.. DevScripts Vulnerability, Ubuntu Security Updates, Remote Code Execution. . Severity: Critical. LinuxSecurity.com Team
Several vulnerabilities have been discovered in uscan, a tool to scan upstream sits for new releases of packages, which is part of the devscripts package. An attacker controlling a website from which uscan would attempt to download a source tarball could execute arbitrary code . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2836-1
Get the latest Linux and open source security news straight to your inbox.