Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 481
Alerts This Week
Warning Icon 1 481

SUSE: 2015:0487-1 Critical: Shell Injection in osc Tool

suse
Calendar Grey March 12, 2015
Scroller Suse
Crucial SUSE update enhances security for osc, addressing vulnerabilities related to shell command injection, thus fortifying system integrity.
An update that fixes one vulnerability is now available

Summary

osc was updated to fix a security issue and some non-security bugs. osc was updated to 0.151.0, fixing the following vulnerability: * fixed shell command injection via crafted _service files CVE-2015-0778 boo#901643 The following non-security bugs were fixed: * fix times when data comes from OBS backend * support updateing the link in target package for submit requests * various minor bugfixes Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12: zypper in -t patch SUSE-SLE-SDK-12-2015-119=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 12 (noarch): osc-0.151.0-8.1

References

#901643

Cross- CVE-2015-0778

Affected Products:

SUSE Linux Enterprise Software Development Kit 12

https://www.suse.com/security/cve/CVE-2015-0778.html

https://bugzilla.suse.com/show_bug.cgi?id=901643

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:0487-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.