scripts/dget.pl in devscripts before 2.10.73 allows remote attackers to execute arbitrary commands via a crafted (1) .dsc or (2) .changes file, related to "arguments to external commands" that are not properly escaped, a different vulnerability than CVE-2012-2240.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2012-09-30 17:55
Updated : 2013-04-18 20:21
NVD link : CVE-2012-2242
Mitre link : CVE-2012-2242
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
devscripts_devel_team
- devscripts