828
VMScore

CVE-2017-9274

Published: 01/03/2018 Updated: 07/11/2023
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

A shell command injection in the obs-service-source_validator prior to 0.7 could be used to execute code as the packager when checking RPM SPEC files with specific macro constructs.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse obs-service-source validator

Vendor Advisories

Debian Bug report logs - #887391 CVE-2017-9274 Package: osc; Maintainer for osc is RPM packaging team <team+pkg-rpm@trackerdebianorg>; Source for osc is src:osc (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 15 Jan 2018 20:15:01 UTC Severity: grave Tags: security Found in versio ...