PT-2018-4340 · Opensuse · Open Build Service

Marcus Huewe

+1

·

Publicado

2018-03-02

·

Atualizado

2019-10-09

·

CVE-2015-0796

CVSS v3.1

6.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions open buildservice versions 2.4 through 2.4.7 open buildservice versions 2.5 through 2.5.6 open buildservice versions 2.6 through 2.6.2
Description The issue allows buildservice users to potentially break out of confinement or cause denial of service attacks on the source service due to the generation of non-standard files like symlinks or device nodes by the source service patch application.
Recommendations For open buildservice versions 2.4 through 2.4.7, update to version 2.4.8 or later. For open buildservice versions 2.5 through 2.5.6, update to version 2.5.7 or later. For open buildservice versions 2.6 through 2.6.2, update to version 2.6.3 or later.

Correção

Link Following

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-0796

Produtos afetados

Open Build Service