Devscripts is a focused collection of utility scripts and tools used by Debian package developers and maintainers to automate common packaging workflows. Its recurring vulnerabilities center on input validation, race conditions, code injection, path traversal, and symlink-following issues that reflect the script-based nature of the tooling and its interaction with the filesystem and build environment. Defenders relying on devscripts should treat security advisories for the package seriously within development pipelines; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Devscripts Devel Team over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-0211HIGH debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via a crafted tarball file name in the top-level directory | Jun 16, 2012 | 9.3 | 29 | NO | NO |
CVE-2012-0210HIGH debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to obtain system information and execute arbitrary code via the file name in a (1) . | Jun 16, 2012 | 9.3 | 29 | NO | NO |
CVE-2009-2946HIGH Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers | Sep 4, 2009 | 9.3 | 29 | NO | NO |
CVE-2012-0212HIGH debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via shell metacharacters in the file name argument. | Jun 16, 2012 | 9.3 | 28 | NO | NO |
CVE-2012-2240HIGH scripts/dscverify.pl in devscripts before 2.12.3 allows remote attackers to execute arbitrary commands via unspecified vectors related to "arguments to external commands." | Oct 1, 2012 | 7.5 | 23 | NO | NO |
CVE-2015-5705HIGH Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers to write to arbitrary files via a crafted symlink and crafted filename. | Sep 6, 2017 | 7.5 | 22 | NO | NO |
CVE-2012-2242MEDIUM scripts/dget.pl in devscripts before 2.10.73 allows remote attackers to execute arbitrary commands via a crafted (1) .dsc or (2) .changes file, related to "arguments to external co | Oct 1, 2012 | 6.8 | 22 | NO | NO |
CVE-2015-5704HIGH scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands. | Sep 25, 2017 | 7.8 | 21 | NO | NO |
CVE-2013-7050MEDIUM The get_main_source_dir function in scripts/uscan.pl in devscripts before 2.13.8, when using USCAN_EXCLUSION, allows remote attackers to execute arbitrary commands via shell metach | Dec 13, 2013 | 6.8 | 21 | NO | NO |
CVE-2013-6888HIGH Uscan in devscripts before 2.13.9 allows remote attackers to execute arbitrary code via a crafted tarball. | Jan 7, 2014 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Devscripts Devel Team.
Media articles that mention a CVE ID that affects a product developed by Devscripts Devel Team — matched by CVE ID, not by vendor name.