PT-2018-4340 · Opensuse · Open Build Service
Marcus Huewe
+1
·
Published
2018-03-02
·
Updated
2019-10-09
·
CVE-2015-0796
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
open buildservice versions 2.4 through 2.4.7
open buildservice versions 2.5 through 2.5.6
open buildservice versions 2.6 through 2.6.2
Description
The issue allows buildservice users to potentially break out of confinement or cause denial of service attacks on the source service due to the generation of non-standard files like symlinks or device nodes by the source service patch application.
Recommendations
For open buildservice versions 2.4 through 2.4.7, update to version 2.4.8 or later.
For open buildservice versions 2.5 through 2.5.6, update to version 2.5.7 or later.
For open buildservice versions 2.6 through 2.6.2, update to version 2.6.3 or later.
Fix
Link Following
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open Build Service