Description
Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Affected products
- SUSE / openSUSE Leap 15.5? – 1.9.0-150400.10.6.1
- SUSE / openSUSE Leap 15.6? – 1.9.0-150400.10.6.1
- SUSE / openSUSE Tumbleweed? – 1.9.0-1.1
- SUSE / SUSE Linux Enterprise Desktop 15 SP5? – 1.9.0-150400.10.6.1
- SUSE / SUSE Linux Enterprise Desktop 15 SP6? – 1.9.0-150400.10.6.1
- SUSE / SUSE Linux Enterprise High Performance Computing 15 SP5? – 1.9.0-150400.10.6.1
- SUSE / SUSE Linux Enterprise High Performance Computing 15 SP6? – 1.9.0-150400.10.6.1
- SUSE / SUSE Linux Enterprise Module for Development Tools 15 SP5? – 1.9.0-150400.10.6.1
- SUSE / SUSE Linux Enterprise Module for Development Tools 15 SP6? – 1.9.0-150400.10.6.1
- SUSE / SUSE Linux Enterprise Server 12 SP5? – 0.183.0-15.18.1
- SUSE / SUSE Linux Enterprise Server 15 SP5? – 1.9.0-150400.10.6.1
- SUSE / SUSE Linux Enterprise Server 15 SP6? – 1.9.0-150400.10.6.1
- SUSE / SUSE Linux Enterprise Server for SAP Applications 12 SP5? – 0.183.0-15.18.1
- SUSE / SUSE Linux Enterprise Server for SAP Applications 15 SP5? – 1.9.0-150400.10.6.1
- SUSE / SUSE Linux Enterprise Server for SAP Applications 15 SP6? – 1.9.0-150400.10.6.1
- SUSE / SUSE Linux Enterprise Software Development Kit 12 SP5? – 0.183.0-15.18.1