LWN.net Logo

susestudio, kiwi: multiple vulnerabilities

Package(s):SUSE Studio Onsite 1.2 and kiwi CVE #(s):CVE-2011-3180 CVE-2011-4192 CVE-2011-4193 CVE-2011-4195
Created:December 15, 2011 Updated:December 21, 2011
Description:

From the SUSE advisory:

  • CVE-2011-3180: The path of overlay files was not escaped which allowed shell meta character injection via the chown(1) command-line. (kiwi)
  • CVE-2011-4195: The image name was not escaped properly and can be used in conjunction with other applications to execute arbitrary shell commands. (kiwi)
  • CVE-2011-4193: XSS vulnerability in "overlay files" tab can be used to execute arbitrary JavaScript code while cloning an appliance from an untrusted source.
  • CVE-2011-4192: Arbitrary shell command injection in conjunction with Studio by using double quotes in kiwi_oemtitle of .profile. (kiwi)
Alerts:
SUSE SUSE-SU-2011:1324-1 2011-12-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds