CVE-2012-2242 Information

Description

scripts/dget.pl in devscripts before 2.10.73 allows remote attackers to execute arbitrary commands via a crafted (1) .dsc or (2) .changes file related to \arguments to external commands\ that are not properly escaped a different vulnerability than CVE-2012-2240.

Reference

http://secunia.com/advisories/50600 http://www.debian.org/security/2012/dsa-2549 http://www.securityfocus.com/bid/55564 http://www.ubuntu.com/usn/USN-1593-1

Share on: