CVE-2011-4183: open build service allows anyone to upload rpms
Published Jun 13, 2018
·Updated
A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE open build service prior to 2.1.16.
Affected Software
1 affected component
openSUSE Open Build Service<2.1.16
Remediation
Event History
Jun 13, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2011-4183?
The severity of CVE-2011-4183 is critical with a CVSS score of 9.8.
2
How does the vulnerability in open build service (CVE-2011-4183) affect SUSE open build service?
The vulnerability affects SUSE open build service versions prior to 2.1.16.
3
How can remote attackers exploit CVE-2011-4183?
Remote attackers can exploit CVE-2011-4183 by uploading arbitrary RPM files.
4
Is there a fix available for CVE-2011-4183?
Yes, the fix for CVE-2011-4183 can be found in the commit 5281e4bff9df31f1f91e22a0d1e9086b93b23d7e in the openSUSE open build service repository.
5
Where can I find more information about CVE-2011-4183?
More information about CVE-2011-4183 can be found in the bugzilla entry: https://bugzilla.suse.com/show_bug.cgi?id=736243