← Back

Devscripts

devscripts

Vendor: Debian • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Debian
1Devscripts
Jun 17, 2026
Aug 1, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP ver...Show more
It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification if the upstream source is already downloaded from a previous run even if the verification failed back then.Show less
1Debian
2Debian Linux
Devscripts
Nov 21, 2024
Dec 3, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue exists in uscan in devscripts before 2.13.19, which could let a remote malicious user execute arbitrary code via a crafted tarball.
2Canonical
Debian
2Devscripts
Ubuntu Linux
Nov 21, 2024
Jul 1, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a configuration that prevents unintended blessing.