rpm package
opensuse/obs-service-tar_scm&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/obs-service-tar_scm&distro=openSUSE%20Tumbleweed
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-56004 | Cri | 10.0 | < 0.12.4-1.1 | 0.12.4-1.1 | Jul 2, 2026 | A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute code as the source service or the local user checking out the malicious services | |
| CVE-2018-12476 | Med | 4.3 | < 0.10.28.1632141620.a8837d3-1.1 | 0.10.28.1632141620.a8837d3-1.1 | Jan 27, 2020 | Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; openSUSE Factory allows remote attackers with control over a repository to overwrite files on the machine of the local user if a malicious service is executed. This issue affects: SUS | |
| CVE-2018-12474 | Med | 5.4 | < 0.10.28.1632141620.a8837d3-1.1 | 0.10.28.1632141620.a8837d3-1.1 | Oct 9, 2018 | Improper input validation in obs-service-tar_scm of Open Build Service allows remote attackers to cause access and extract information outside the current build or cause the creation of file in attacker controlled locations. Affected releases are openSUSE Open Build Service: vers | |
| CVE-2018-12473 | Low | 3.1 | < 0.10.28.1632141620.a8837d3-1.1 | 0.10.28.1632141620.a8837d3-1.1 | Oct 2, 2018 | A path traversal traversal vulnerability in obs-service-tar_scm of Open Build Service allows remote attackers to cause access files not in the current build. On the server itself this is prevented by confining the worker via KVM. Affected releases are openSUSE Open Build Service: |
- affected < 0.12.4-1.1fixed 0.12.4-1.1
A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute code as the source service or the local user checking out the malicious services
- affected < 0.10.28.1632141620.a8837d3-1.1fixed 0.10.28.1632141620.a8837d3-1.1
Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; openSUSE Factory allows remote attackers with control over a repository to overwrite files on the machine of the local user if a malicious service is executed. This issue affects: SUS
- affected < 0.10.28.1632141620.a8837d3-1.1fixed 0.10.28.1632141620.a8837d3-1.1
Improper input validation in obs-service-tar_scm of Open Build Service allows remote attackers to cause access and extract information outside the current build or cause the creation of file in attacker controlled locations. Affected releases are openSUSE Open Build Service: vers
- affected < 0.10.28.1632141620.a8837d3-1.1fixed 0.10.28.1632141620.a8837d3-1.1
A path traversal traversal vulnerability in obs-service-tar_scm of Open Build Service allows remote attackers to cause access files not in the current build. On the server itself this is prevented by confining the worker via KVM. Affected releases are openSUSE Open Build Service: