In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could generate non-standard files like symlinks or device nodes, which could allow buildservice users to break of confinement or cause denial of service attacks on the source service.
2018-03-02T20:29:00.207
2024-11-21T02:23:43.580
Modified
CVSSv3.0: 6.3 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | opensuse | open_buildservice | < 2.4.8 | Yes |
Application | opensuse | open_buildservice | < 2.5.7 | Yes |
Application | opensuse | open_buildservice | < 2.6.3 | Yes |