devscripts contains a flaw that is triggered when certain input passed via dverify is not properly verified before being used in an external command argument. With a specially crafted source package, a context-dependent attacker can execute arbitrary code.
Classification
Location:
Context Dependent
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Third-Party Solution
Exploit:
Exploit Unknown
Disclosure:
Third-party Verified
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, Debian has released updated packages to address this vulnerability. Check the vendor advisory or solution in the references section.