First published: Mon Mar 16 2015(Updated: )
osc before 0.151.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a _service file.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Fedora | =20 | |
Fedora | =21 | |
Fedora | =22 | |
openSUSE | <=0.150 | |
SUSE Linux | =13.1 | |
SUSE Linux | =13.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0778 is categorized as a medium severity vulnerability due to its potential for arbitrary command execution.
To fix CVE-2015-0778, update osc to version 0.151.0 or later.
CVE-2015-0778 affects Fedora versions 20, 21, 22 and openSUSE versions up to 0.150.
CVE-2015-0778 is a command injection vulnerability that allows execution of arbitrary commands using shell metacharacters.
Yes, CVE-2015-0778 can be exploited by remote attackers if the vulnerable software is exposed.