CVE-2025-8454 – Debian Package devscripts OpenPGP Verification Bypass

The following table lists the changes that have been made to the
CVE-2025-8454 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Aug. 01, 2025

    Action Type Old Value New Value
    Added Description It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification for files already downloaded even if a previous verification did fail.
    Added Reference https://bugs.debian.org/1109251
Share the Post:

Related Posts