open build service source server symlink exploitation via source patch
Vulnerability Description
In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could generate non-standard files like symlinks or device nodes, which could allow buildservice users to break of confinement or cause denial of service attacks on the source service.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-0796
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Marcus Hüwe
References
More from SUSE
View All →Affected Vendor
SUSE
View all reports →