Back to Database
Status published
Medium
CVE-2012-2241
scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete...
Vulnerability Description
scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete arbitrary files via a crafted (1) .dsc or (2) .changes file, probably related to a NULL byte in a filename.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-2241
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/55564
- http://www.debian.org/security/2012/dsa-2549
- http://secunia.com/advisories/50600
- http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git%3Ba=commitdiff%3Bh=0fd15bdec07b085f9ef438dacd18e159ac60b810
- http://www.ubuntu.com/usn/USN-1593-1
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78977
More from devscripts devel team
View All →CVE-2015-5705
Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers...
High
7.5
CVE-2015-5704
scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute...
High
7.8
CVE-2014-1833
Directory traversal vulnerability in uupdate in devscripts 2.14.1 allows remote...
Medium
5
CVE-2013-7085
Uscan in devscripts 2.13.5, when USCAN_EXCLUSION is enabled, allows remote...
Medium
5.8
CVE-2013-7050
The get_main_source_dir function in scripts/uscan.pl in devscripts before 2.13.8, when...
Medium
6.8
Affected Vendor
devscripts devel team
View all reports →Affected Software
devscripts
Vulnerable Versions:
0, 2.7.0, 2.8.14, 2.9.21, 2.9.22, 2.9.23, 2.9.24, 2.9.25, 2.9.26, 2.9.27, 2.10.0, 2.10.1, 2.10.3, 2.10.6, 2.10.7, 2.10.8, 2.10.9, 2.10.10, 2.10.11, 2.10.12, 2.10.13, 2.10.14, 2.10.15, 2.10.16, 2.10.17, 2.10.18, 2.10.18.1, 2.10.19, 2.10.20, 2.10.21, 2.10.22, 2.10.23, 2.10.24, 2.10.25, 2.10.26, 2.10.27, 2.10.28, 2.10.29, 2.10.30, 2.10.31, 2.10.32, 2.10.33, 2.10.34, 2.10.35, 2.10.36, 2.10.38, 2.10.39, 2.10.40, 2.10.41, 2.10.42, 2.10.43, 2.10.44, 2.10.45, 2.10.46, 2.10.47, 2.10.48, 2.10.49, 2.10.50, 2.10.51, 2.10.52, 2.10.53, 2.10.54, 2.10.55, 2.10.56, 2.10.57, 2.10.58, 2.10.59, 2.10.60, 2.10.61, 2.10.62, 2.10.63, 2.10.64, 2.10.65.1, 2.10.66, 2.10.67, 2.10.68, 2.11.0, 2.11.1, 2.11.2, 2.11.3, 2.11.4, 2.11.5, 2.11.6, 2.11.7, 2.11.8, 2.11.9, 2.12.0, 2.12.1
Timeline
Official Publish:
October 1st, 2012
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.