CVE-2018-12474
Summary
| CVE | CVE-2018-12474 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-10-09 13:29:00 UTC |
| Updated | 2023-11-07 02:52:00 UTC |
| Description | Improper input validation in obs-service-tar_scm of Open Build Service allows remote attackers to cause access and extract information outside the current build or cause the creation of file in attacker controlled locations. Affected releases are openSUSE Open Build Service: versions prior to 51a17c553b6ae2598820b7a90fd0c11502a49106. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| fix regression from 44b3bee by M0ses · Pull Request #254 · openSUSE/obs-service-tar_scm · GitHub | CONFIRM | github.com | Third Party Advisory |
| Bug 1107507 – VUL-0: CVE-2018-12474: obs-service-tar_scm: crafted service parameters allow unexpected behaviour | bugzilla.suse.com | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Matthias Gerstner of SUSE
There are currently no legacy QID mappings associated with this CVE.