First published: Mon Mar 03 2014(Updated: )
The set_version script as shipped with obs-service-set_version is a source validator for the Open Build Service (OBS). In versions prior to 0.5.3-1.1 this script did not properly sanitize the input provided by the user, allowing for code execution on the executing server.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE Open Build Service | >=0.5.3<1.1 |
https://github.com/openSUSE/obs-service-set_version/commit/10d5bddcea29f74a175f7f550924bf6407e52e93
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0593 is a vulnerability in the set_version script of obs-service-set_version, allowing for code execution on the executing server.
CVE-2014-0593 affects openSUSE Open Build Service versions prior to 0.5.3-1.1.
CVE-2014-0593 has a severity rating of 9.8 (Critical).
To fix CVE-2014-0593, upgrade obs-service-set_version to version 0.5.3-1.1 or later.
More information about CVE-2014-0593 can be found at the following references: [1] [2] [3]