CVE-2025-8454

It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification if the upstream source is already downloaded from a previous run even if the verification failed back then.
References
Link Resource
https://bugs.debian.org/1109251 Issue Tracking Mailing List
Configurations

Configuration 1 (hide)

cpe:2.3:a:debian:devscripts:2.25.15:*:*:*:*:*:*:*

History

06 Aug 2025, 16:17

Type Values Removed Values Added
References () https://bugs.debian.org/1109251 - () https://bugs.debian.org/1109251 - Issue Tracking, Mailing List
First Time Debian devscripts
Debian
CPE cpe:2.3:a:debian:devscripts:2.25.15:*:*:*:*:*:*:*

01 Aug 2025, 14:15

Type Values Removed Values Added
CWE CWE-347
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
Summary
  • (es) Se descubrió que uscan, una herramienta para escanear o vigilar fuentes originales en busca de nuevas versiones de software, incluida en devscripts (una colección de scripts para facilitar la vida del mantenedor de paquetes Debian), omite la verificación OpenPGP para archivos ya descargados incluso si una verificación previa falló.

01 Aug 2025, 08:15

Type Values Removed Values Added
Summary (en) It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification for files already downloaded even if a previous verification did fail. (en) It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification if the upstream source is already downloaded from a previous run even if the verification failed back then.

01 Aug 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-01 06:15

Updated : 2025-08-06 16:17


NVD link : CVE-2025-8454

Mitre link : CVE-2025-8454

CVE.ORG link : CVE-2025-8454


JSON object : View

Products Affected

debian

  • devscripts
CWE
CWE-347

Improper Verification of Cryptographic Signature