First published: Thu Mar 01 2018(Updated: )
A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files with specific macro constructs.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Opensuse Obs-service-source Validator | <0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-9274 is rated as critical with a score of 7.8.
To fix CVE-2017-9274, upgrade the obs-service-source_validator to version 0.7 or later.
CVE-2017-9274 exploits a shell command injection vulnerability in the obs-service-source_validator.
Users of obs-service-source_validator versions before 0.7 are affected by CVE-2017-9274.
CVE-2017-9274 is associated with command injection vulnerabilities, specifically CWE-77 and CWE-78.