CVE-2014-0593: sed command injection
Published Jun 8, 2018
·Updated
The setversion script as shipped with obs-service-setversion is a source validator for the Open Build Service (OBS). In versions prior to 0.5.3-1.1 this script did not properly sanitize the input provided by the user, allowing for code execution on the executing server.
Affected Software
1 affected component
openSUSE Open Build Service>=0.5.3<1.1
Remediation
Event History
Jun 8, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2014-0593?
CVE-2014-0593 is a vulnerability in the set_version script of obs-service-set_version, allowing for code execution on the executing server.
2
How does CVE-2014-0593 affect openSUSE Open Build Service?
CVE-2014-0593 affects openSUSE Open Build Service versions prior to 0.5.3-1.1.
3
What is the severity of CVE-2014-0593?
CVE-2014-0593 has a severity rating of 9.8 (Critical).
4
How can I fix CVE-2014-0593?
To fix CVE-2014-0593, upgrade obs-service-set_version to version 0.5.3-1.1 or later.
5
Where can I find more information about CVE-2014-0593?
More information about CVE-2014-0593 can be found at the following references: [1] [2] [3]