Debian: 2836-1: devscripts: arbitrary code execution
(Jan 5) Several vulnerabilities have been discovered in uscan, a tool to scan upstream sits for new releases of packages, which is part of the devscripts package. An attacker controlling a website from which uscan would attempt to download a source tarball could execute arbitrary code [More…]