PT-2018-4340 · Opensuse · Open Build Service

Marcus Huewe

+1

·

Published

2018-03-02

·

Updated

2019-10-09

·

CVE-2015-0796

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions open buildservice versions 2.4 through 2.4.7 open buildservice versions 2.5 through 2.5.6 open buildservice versions 2.6 through 2.6.2
Description The issue allows buildservice users to potentially break out of confinement or cause denial of service attacks on the source service due to the generation of non-standard files like symlinks or device nodes by the source service patch application.
Recommendations For open buildservice versions 2.4 through 2.4.7, update to version 2.4.8 or later. For open buildservice versions 2.5 through 2.5.6, update to version 2.5.7 or later. For open buildservice versions 2.6 through 2.6.2, update to version 2.6.3 or later.

Fix

Link Following

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-0796

Affected Products

Open Build Service