obs-service-refresh_patches can be tricked into deleting '..' or other unrelated directories
Description
A Improper Neutralization of CRLF Sequences vulnerability in Open Build Service allows remote attackers to cause deletion of directories by tricking obs-service-refresh_patches to delete them. Affected releases are openSUSE Open Build Service: versions prior to d6244245dda5367767efc989446fe4b5e4609cce.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
obs-service-refresh_patches in openSUSE Build Service before commit d6244245dda5 can be tricked into deleting arbitrary directories via a crafted package.
Vulnerability
CVE-2018-12477 is an improper neutralization of CRLF sequences in the obs-service-refresh_patches component of openSUSE Open Build Service. The service failed to properly sanitize file paths extracted from package archives, allowing an attacker to inject path traversal sequences such as ... This vulnerability affects all versions of Open Build Service prior to commit d6244245dda5367767efc989446fe4b5e4609cce [1].
Exploitation
An attacker must be able to provide a crafted package to an Open Build Service instance that uses the obs-service-refresh_patches service. By including specially crafted file names or patch references containing CRLF or path traversal sequences, the attacker can cause the service to delete directories outside of the intended working area. No authentication beyond the ability to submit a package is required, but successful exploitation depends on the service processing the malicious input [1].
Impact
Successful exploitation allows an attacker to delete arbitrary directories on the server where the Open Build Service runs. This can lead to denial of service by removing critical system or application directories, potentially affecting the integrity and availability of the build service and its hosted projects [1].
Mitigation
The vulnerability was fixed in the Open Build Service source repository by commit d6244245dda5367767efc989446fe4b5e4609cce. Users should update to a version that includes this commit or apply the patch manually. The official fix was published on 2018-10-09. No workaround is documented in the available references [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Range: < d6244245dda5367767efc989446fe4b5e4609cce
- osv-coordsRange: < 0.3.9+git.1625238904.d59f20e-1.2
- openSUSE/Open Build Servicev5Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- bugzilla.suse.com/show_bug.cgimitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.