Vulnerability Description
Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; openSUSE Factory allows remote attackers with control over a repository to overwrite files on the machine of the local user if a malicious service is executed. This issue affects: SUSE Linux Enterprise Server 15 obs-service-tar_scm versions prior to 0.9.2.1537788075.fefaa74:. openSUSE Factory obs-service-tar_scm versions prior to 0.9.2.1537788075.fefaa74.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Suse | Obs-Service-Tar Scm | < 0.9.2.1537788075.fefaa74 |
| Suse | Suse Linux Enterprise Server | 15 |
| Suse | Opensuse Factory | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2018-12476?
CVE-2018-12476 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; openSUSE Factory allows remote attackers with control over a repository to overwrite files on the machi...
How severe is CVE-2018-12476?
CVE-2018-12476 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-12476?
Check the references section above for vendor advisories and patch information. Affected products include: Suse Obs-Service-Tar Scm, Suse Suse Linux Enterprise Server, Suse Opensuse Factory.