First published: Wed Jun 13 2018(Updated: )
A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE open build service prior to 2.1.16.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE Open Build Service | <2.1.16 |
https://github.com/openSUSE/open-build-service/commit/5281e4bff9df31f1f91e22a0d1e9086b93b23d7e
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2011-4183 is critical with a CVSS score of 9.8.
The vulnerability affects SUSE open build service versions prior to 2.1.16.
Remote attackers can exploit CVE-2011-4183 by uploading arbitrary RPM files.
Yes, the fix for CVE-2011-4183 can be found in the commit 5281e4bff9df31f1f91e22a0d1e9086b93b23d7e in the openSUSE open build service repository.
More information about CVE-2011-4183 can be found in the bugzilla entry: https://bugzilla.suse.com/show_bug.cgi?id=736243