{"id":"DEBIAN-CVE-2025-8454","details":"It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification if the upstream source is already downloaded from a previous run even if the verification failed back then.","modified":"2026-09-01T20:05:59.005012148Z","published":"2025-08-01T06:15:29.493Z","upstream":["CVE-2025-8454"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-8454"}],"affected":[{"package":{"name":"devscripts","ecosystem":"Debian:12","purl":"pkg:deb/debian/devscripts?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.23.4","2.23.4+deb12u1","2.23.4+deb12u2","2.23.5","2.23.5~bpo11+1","2.23.6","2.23.6~bpo11+1","2.23.7","2.23.7~bpo11+1","2.24.1","2.24.10","2.24.2","2.24.3","2.24.4","2.24.5","2.24.6","2.24.7","2.24.8","2.24.9","2.25.1","2.25.10","2.25.10~bpo12+1","2.25.11","2.25.12","2.25.13","2.25.14","2.25.15","2.25.15~bpo12+1","2.25.16","2.25.17","2.25.18","2.25.19","2.25.19~bpo13+1","2.25.2","2.25.20","2.25.21","2.25.22","2.25.22~bpo13+1","2.25.23","2.25.24","2.25.25","2.25.26","2.25.27","2.25.28","2.25.29","2.25.3","2.25.30","2.25.31","2.25.32","2.25.33","2.25.4","2.25.5","2.25.6","2.25.7","2.25.8","2.25.8~bpo12+1","2.25.9","2.26.1","2.26.10","2.26.11","2.26.11~bpo13+1","2.26.2","2.26.3","2.26.4","2.26.5","2.26.6","2.26.6~bpo13+1","2.26.7","2.26.7~bpo13+1","2.26.8","2.26.9","2.26.9~bpo13+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-8454.json"}},{"package":{"name":"devscripts","ecosystem":"Debian:13","purl":"pkg:deb/debian/devscripts?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.25.15","2.25.15+deb13u1","2.25.16","2.25.17","2.25.18","2.25.19","2.25.19~bpo13+1","2.25.20","2.25.21","2.25.22","2.25.22~bpo13+1","2.25.23","2.25.24","2.25.25","2.25.26","2.25.27","2.25.28","2.25.29","2.25.30","2.25.31","2.25.32","2.25.33","2.26.1","2.26.10","2.26.11","2.26.11~bpo13+1","2.26.2","2.26.3","2.26.4","2.26.5","2.26.6","2.26.6~bpo13+1","2.26.7","2.26.7~bpo13+1","2.26.8","2.26.9","2.26.9~bpo13+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-8454.json"}},{"package":{"name":"devscripts","ecosystem":"Debian:14","purl":"pkg:deb/debian/devscripts?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.25.15","2.25.16","2.25.17","2.25.18","2.25.19","2.25.19~bpo13+1","2.25.20","2.25.21","2.25.22","2.25.22~bpo13+1","2.25.23","2.25.24","2.25.25","2.25.26","2.25.27","2.25.28","2.25.29","2.25.30","2.25.31","2.25.32","2.25.33","2.26.1","2.26.10","2.26.11","2.26.11~bpo13+1","2.26.2","2.26.3","2.26.4","2.26.5","2.26.6","2.26.6~bpo13+1","2.26.7","2.26.7~bpo13+1","2.26.8","2.26.9","2.26.9~bpo13+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-8454.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}