Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 21: FEDORA-2015-4482 Critical: osc Shell Injection

fedora
Calendar Grey April 5, 2015
Dist Fedora Esm H88
Fedora 22's dnf addresses a serious security flaw concerning shell escape risk CVE-2015-0832 to bolster overall security.
Security fix for CVE-2015-0778

Summary

Commandline client for the openSUSE Build Service.

See https://en.opensuse.org/openSUSE:OSC , as well as

https://en.opensuse.org/openSUSE:Build_Service_Tutorial for a general

introduction.

Update Information:

Security fix for CVE-2015-0778

Change Log

* Tue Feb 24 2015 Miroslav Suchý 0.151.1-163.2.1 - rebase to 0.140.1 - fixed shell command injection via crafted _service files CVE-2015-0778

References


[ 1 ] Bug #1201773 - CVE-2015-0778 osc: osc _service file shell injection flaw https://bugzilla.redhat.com/show_bug.cgi?id=1201773

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update osc' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: osc
Product: Fedora 21
Version: 0.151.1
Release: 163.2.1.fc21
Summary: The openSUSE Build Service Commander

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here