CVE-2011-3180: High severity SUSE Studio Extension for System z vulnerability
kiwi before 4.98.08, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in the path of an overlay file, related to chown.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3180?
CVE-2011-3180 is considered to have a medium severity due to its potential to allow arbitrary command execution.
How do I fix CVE-2011-3180?
To fix CVE-2011-3180, update to the latest version of the affected software, specifically kiwi version 4.98.08 or later, or SUSE Studio Onsite and Extension for System z version 1.2.1 or later.
Which versions are affected by CVE-2011-3180?
CVE-2011-3180 affects kiwi versions prior to 4.98.08 and SUSE Studio Onsite and Extension for System z versions 1.2 before 1.2.1.
What type of vulnerability is CVE-2011-3180?
CVE-2011-3180 is a command injection vulnerability that allows attackers to execute arbitrary commands through the misuse of file paths.
Who can be impacted by CVE-2011-3180?
Users of the affected versions of SUSE Studio Onsite and extension, as well as those utilizing vulnerable versions of kiwi, are impacted by CVE-2011-3180.