First published: Sun Apr 10 2011(Updated: )
The API in SUSE openSUSE Build Service (OBS) 2.0.x before 2.0.8 and 2.1.x before 2.1.6 allows attackers to bypass intended write-access restrictions and modify a (1) package or (2) project via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Opensuse Build Service | =2.0.103 | |
Novell Opensuse Build Service | =2.0 | |
Novell Opensuse Build Service | =2.0.106 | |
Novell Opensuse Build Service | =2.0.16 | |
Novell Opensuse Build Service | =2.0.2 | |
Novell Opensuse Build Service | =2.0.7 | |
Novell Opensuse Build Service | =2.0.0 | |
Novell Opensuse Build Service | =2.0.5 | |
Novell Opensuse Build Service | =2.0.1 | |
Novell Opensuse Build Service | =2.0.104 | |
Novell Opensuse Build Service | =2.0.6 | |
Novell Opensuse Build Service | =2.0.4 | |
Novell Opensuse Build Service | =2.0.3 | |
Novell Opensuse Build Service | =2.1.4 | |
Novell Opensuse Build Service | =2.1.5.1 | |
Novell Opensuse Build Service | =2.1.3 | |
Novell Opensuse Build Service | =2.1.0 | |
Novell Opensuse Build Service | =2.1.1 | |
Novell Opensuse Build Service | =2.1.5 | |
Novell Opensuse Build Service | =2.1.2 | |
Novell Opensuse Build Service | =2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0466 has a medium severity rating, allowing attackers to bypass write-access restrictions.
You can fix CVE-2011-0466 by upgrading to SUSE openSUSE Build Service version 2.0.8 or later, or 2.1.6 or later.
CVE-2011-0466 affects versions 2.0.x before 2.0.8 and 2.1.x before 2.1.6.
CVE-2011-0466 is a security vulnerability that allows unauthorized modification of packages or projects.
Organizations using vulnerable versions of SUSE openSUSE Build Service for package management are impacted by CVE-2011-0466.