CVE-2013-7050: Devscripts Devel Team Devscripts

Medium severity, CVSS 6.8. EPSS: 1.9% chance of exploitation in the next 30 days.

The get_main_source_dir function in scripts/uscan.pl in devscripts before 2.13.8, when using USCAN_EXCLUSION, allows remote attackers to execute arbitrary commands via shell metacharacters in a directory name.

Affected products

  • Devscripts Devel Team Devscripts: up to and including 2.13.7; version 2.13.0 only; version 2.13.1 only; version 2.13.2 only; version 2.13.3 only; version 2.13.4 only; …

Published 2013-12-13. Last modified 2026-06-17.