Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

SUSE: 2015:0487-1 Critical: Shell Injection in osc Tool

suse
Calendar Grey March 12, 2015
Dist Suse Esm H88
Crucial SUSE update enhances security for osc, addressing vulnerabilities related to shell command injection, thus fortifying system integrity.
An update that fixes one vulnerability is now available

Summary

osc was updated to fix a security issue and some non-security bugs. osc was updated to 0.151.0, fixing the following vulnerability: * fixed shell command injection via crafted _service files CVE-2015-0778 boo#901643 The following non-security bugs were fixed: * fix times when data comes from OBS backend * support updateing the link in target package for submit requests * various minor bugfixes Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12: zypper in -t patch SUSE-SLE-SDK-12-2015-119=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 12 (noarch): osc-0.151.0-8.1

References

#901643

Cross- CVE-2015-0778

Affected Products:

SUSE Linux Enterprise Software Development Kit 12

https://www.suse.com/security/cve/CVE-2015-0778.html

https://bugzilla.suse.com/show_bug.cgi?id=901643

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:0487-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here