PT-2018-4340 · Opensuse · Open Build Service
Marcus Huewe
+1
·
Publicado
2018-03-02
·
Atualizado
2019-10-09
·
CVE-2015-0796
CVSS v3.1
6.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
open buildservice versions 2.4 through 2.4.7
open buildservice versions 2.5 through 2.5.6
open buildservice versions 2.6 through 2.6.2
Description
The issue allows buildservice users to potentially break out of confinement or cause denial of service attacks on the source service due to the generation of non-standard files like symlinks or device nodes by the source service patch application.
Recommendations
For open buildservice versions 2.4 through 2.4.7, update to version 2.4.8 or later.
For open buildservice versions 2.5 through 2.5.6, update to version 2.5.7 or later.
For open buildservice versions 2.6 through 2.6.2, update to version 2.6.3 or later.
Correção
Link Following
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Open Build Service