The get_main_source_dir function in scripts/uscan.pl in devscripts before 2.13.8, when using USCAN_EXCLUSION, allows remote attackers to execute arbitrary commands via shell metacharacters in a directory name.
| Software | From | Fixed in |
|---|---|---|
| devscripts_devel_team / devscripts | 2.13.5 | 2.13.5.x |
| devscripts_devel_team / devscripts | 2.13.2 | 2.13.2.x |
| devscripts_devel_team / devscripts | - | 2.13.7.x |
| devscripts_devel_team / devscripts | 2.13.4 | 2.13.4.x |
| devscripts_devel_team / devscripts | 2.13.1 | 2.13.1.x |
| devscripts_devel_team / devscripts | 2.13.0 | 2.13.0.x |
| devscripts_devel_team / devscripts | 2.13.6 | 2.13.6.x |
| devscripts_devel_team / devscripts | 2.13.3 | 2.13.3.x |