PT-2018-3448 · Opensuse+1 · Obs-Service-Tar Scm+3
Matthias Gerstner
·
Publicado
2018-06-14
·
Atualizado
2024-06-15
·
CVE-2018-12476
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
SUSE Linux Enterprise Server 15 obs-service-tar scm versions prior to 0.9.2.1537788075.fefaa74
openSUSE Factory obs-service-tar scm versions prior to 0.9.2.1537788075.fefaa74
Description:
The issue is related to a Relative Path Traversal vulnerability in the obs-service-tar scm service, which can be exploited by remote attackers with control over a repository to overwrite files on the local user's machine. This can occur if a malicious service is executed. The vulnerability is associated with incorrect restriction of the directory path name, potentially allowing an attacker to gain unauthorized access to protected information or execute arbitrary code.
Recommendations:
For SUSE Linux Enterprise Server 15 obs-service-tar scm versions prior to 0.9.2.1537788075.fefaa74, update to version 0.9.2.1537788075.fefaa74 or later.
For openSUSE Factory obs-service-tar scm versions prior to 0.9.2.1537788075.fefaa74, update to version 0.9.2.1537788075.fefaa74 or later.
As a temporary workaround, consider restricting access to the obs-service-tar scm service until a patch is applied.
Correção
Relative Path Traversal
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Suse Linux Enterprise Server
Suse
Obs-Service-Tar Scm
Opensuse