First published: Thu Mar 01 2018(Updated: )
The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside of the package source directory during build, allowing leakage of private information.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE Open Build Service | <=2.7.3 |
https://github.com/openSUSE/open-build-service/commit/ba27c91351878bc297ec4baba0bd488a2f3b568d
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this security issue is CVE-2017-5188.
The title of this vulnerability is 'The bs_worker code in open build service before 20170320 followed relative symlinks allowing reading…'
The severity of CVE-2017-5188 is high, with a severity value of 7.5.
The openSUSE Open Build Service version up to and including 2.7.3 is affected by CVE-2017-5188.
To fix the vulnerability, update the openSUSE Open Build Service to a version later than 20170320.