VYPR

rpm package

suse/obs-service-source_validator&distro=SUSE Linux Enterprise Software Development Kit 12 SP2

pkg:rpm/suse/obs-service-source_validator&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2

Vulnerabilities (3)

  • CVE-2017-9274Mar 1, 2018
    affected < 0.7-9.3.1fixed 0.7-9.3.1

    A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files with specific macro constructs.

  • CVE-2017-14804Mar 1, 2018
    affected < 0.7-9.3.1fixed 0.7-9.3.1

    The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.

  • CVE-2010-4226HigFeb 6, 2014
    affected < 0.7-9.3.1fixed 0.7-9.3.1

    cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive.