PT-2018-3448 · Opensuse+1 · Obs-Service-Tar Scm+3

Matthias Gerstner

·

Published

2018-06-14

·

Updated

2024-06-15

·

CVE-2018-12476

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: SUSE Linux Enterprise Server 15 obs-service-tar scm versions prior to 0.9.2.1537788075.fefaa74 openSUSE Factory obs-service-tar scm versions prior to 0.9.2.1537788075.fefaa74
Description: The issue is related to a Relative Path Traversal vulnerability in the obs-service-tar scm service, which can be exploited by remote attackers with control over a repository to overwrite files on the local user's machine. This can occur if a malicious service is executed. The vulnerability is associated with incorrect restriction of the directory path name, potentially allowing an attacker to gain unauthorized access to protected information or execute arbitrary code.
Recommendations: For SUSE Linux Enterprise Server 15 obs-service-tar scm versions prior to 0.9.2.1537788075.fefaa74, update to version 0.9.2.1537788075.fefaa74 or later. For openSUSE Factory obs-service-tar scm versions prior to 0.9.2.1537788075.fefaa74, update to version 0.9.2.1537788075.fefaa74 or later. As a temporary workaround, consider restricting access to the obs-service-tar scm service until a patch is applied.

Fix

Relative Path Traversal

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01574
CVE-2018-12476
OPENSUSE-SU-2019:0326-1
OPENSUSE-SU-2019:0329-1
OPENSUSE-SU-2019_0326-1
OPENSUSE-SU-2024:11107-1
SUSE-SU-2019:0540-1

Affected Products

Suse Linux Enterprise Server
Suse
Obs-Service-Tar Scm
Opensuse