CVE-2018-13043

scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a configuration that prevents unintended blessing.
References
Link Resource
https://bugs.debian.org/902409 Patch Vendor Advisory
https://usn.ubuntu.com/3704-1/ Third Party Advisory
https://bugs.debian.org/902409 Patch Vendor Advisory
https://usn.ubuntu.com/3704-1/ Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:debian:devscripts:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

History

21 Nov 2024, 03:46

Type Values Removed Values Added
References () https://bugs.debian.org/902409 - Patch, Vendor Advisory () https://bugs.debian.org/902409 - Patch, Vendor Advisory
References () https://usn.ubuntu.com/3704-1/ - Third Party Advisory () https://usn.ubuntu.com/3704-1/ - Third Party Advisory

Information

Published : 2018-07-01 22:29

Updated : 2024-11-21 03:46


NVD link : CVE-2018-13043

Mitre link : CVE-2018-13043

CVE.ORG link : CVE-2018-13043


JSON object : View

Products Affected

canonical

  • ubuntu_linux

debian

  • devscripts
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')