Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

SUSE: 2018:0065-1 Important Security Fixes For OBS Toolchain

suse
Calendar Grey January 11, 2018
Scroller Suse
This significant Debian patch addresses several concerns in the APT system with essential improvements and adjustments.
An update that solves three vulnerabilities and has 5 fixes is now available.

Summary

This OBS toolchain update fixes the following issues: Package 'build': - CVE-2017-14804: Improve file name check extractbuild (bsc#1069904) - Fixed Dockerfile repository parsing Package 'obs-service-source_validator': - CVE-2017-9274: Don't use rpmbuild to extract sources, patches etc. from a spec (bnc#938556). - CVE-2016-4007: Several maintained source services are vulnerable to code/paramter injection (bsc#967265) - Update to version 0.7. - Use spec_query instead of output_versions using the specfile parser from the build package (boo#1059858) - obs-service-source_validator: several occurrences of uninitialized value (bsc#967610) - hack for util-linux specfiles (bnc#891829) - fix dependency to gnupg2 for Fedora (bnc#827480) - exit if tmpdir creation fails (bnc#796918) Package 'osc':

References

#1059858 #1069904 #796918 #827480 #891829

#938556 #967265 #967610

Cross- CVE-2016-4007 CVE-2017-14804 CVE-2017-9274

Affected Products:

SUSE Linux Enterprise Software Development Kit 11-SP4

https://www.suse.com/security/cve/CVE-2016-4007.html

https://www.suse.com/security/cve/CVE-2017-14804.html

https://www.suse.com/security/cve/CVE-2017-9274.html

https://bugzilla.suse.com/1059858

https://bugzilla.suse.com/1069904

https://bugzilla.suse.com/796918

https://bugzilla.suse.com/827480

https://bugzilla.suse.com/891829

https://bugzilla.suse.com/938556

https://bugzilla.suse.com/967265

https://bugzilla.suse.com/967610

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:0065-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.