PT-2018-8496 · Opensuse+1 · Obs-Service-Source Validator+1

Christian Boltz

·

Published

2017-12-08

·

Updated

2024-06-15

·

CVE-2017-9274

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions obs-service-source validator versions prior to 0.7
Description A shell command injection issue exists in the handling of RPM SPEC files with specific macro constructs, potentially allowing code execution as the packager.
Recommendations For versions prior to 0.7, update to version 0.7 or later to resolve the issue.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-9274
OPENSUSE-SU-2017_3259-1
OPENSUSE-SU-2024:11106-1
SUSE-SU-2017:3253-1
SUSE-SU-2018:0065-1

Affected Products

Suse
Obs-Service-Source Validator