It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification if the upstream source is already downloaded from a previous run even if the verification failed back then.
References
| Link | Resource |
|---|---|
| https://bugs.debian.org/1109251 | Issue Tracking Mailing List |
Configurations
History
17 Jun 2026, 10:07
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (es) Se descubrió que uscan, una herramienta para escanear o vigilar fuentes originales en busca de nuevas versiones de software, incluida en devscripts (una colección de scripts para facilitar la vida del fabricante de paquetes Debian), omite la verificación OpenPGP para archivos ya descargados incluso si una verificación previa falló. |
06 Aug 2025, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:debian:devscripts:2.25.15:*:*:*:*:*:*:* | |
| References | () https://bugs.debian.org/1109251 - Issue Tracking, Mailing List | |
| First Time |
Debian devscripts
Debian |
01 Aug 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| CWE | CWE-347 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
01 Aug 2025, 08:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification if the upstream source is already downloaded from a previous run even if the verification failed back then. |
01 Aug 2025, 06:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-08-01 06:15
Updated : 2026-06-17 10:07
NVD link : CVE-2025-8454
Mitre link : CVE-2025-8454
CVE.ORG link : CVE-2025-8454
JSON object : View
Products Affected
debian
- devscripts
CWE
CWE-347
Improper Verification of Cryptographic Signature
