High severity7.8NVD Advisory· Published Mar 1, 2018· Updated Jun 17, 2026
CVE-2017-9274
CVE-2017-9274
Description
A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files with specific macro constructs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11- cpe:2.3:a:opensuse:obs-service-source_validator:*:*:*:*:*:*:*:*Range: <0.7
- osv-coords9 versionspkg:rpm/opensuse/obs-service-source_validator&distro=openSUSE%20Tumbleweedpkg:rpm/suse/build&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/build&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/build&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/obs-service-source_validator&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/obs-service-source_validator&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/osc&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/osc&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/osc&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3
< 0.21-1.3+ 8 more
- (no CPE)range: < 0.21-1.3
- (no CPE)range: < 20171128-8.3.3
- (no CPE)range: < 20171128-9.3.2
- (no CPE)range: < 20171128-9.3.2
- (no CPE)range: < 0.7-9.3.1
- (no CPE)range: < 0.7-9.3.1
- (no CPE)range: < 0.162.1-7.4.1
- (no CPE)range: < 0.162.0-15.3.1
- (no CPE)range: < 0.162.0-15.3.1
- SUSE/obs-service-source_validatorv5Range: unspecified
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.