SUSE-SU-2017:3253-1
Dashboard / Vulnerabilities / SUSE-SU-2017:3253-1
SUSE-SU-2017:3253-1
Summary: Fixing security issues on OBS toolchain
Details: This OBS toolchain update fixes the following issues: Package 'build': - CVE-2010-4226: force use of bsdtar for VMs (bnc#665768) - CVE-2017-14804: Improve file name check extractbuild (bsc#1069904) - switch baselibs scheme for debuginfo packages from foo-debuginfo-32bit to foo-32bit-debuginfo (fate#323217) Package 'obs-service-source_validator': - CVE-2017-9274: Don't use rpmbuild to extract sources, patches etc. from a spec (bnc#938556). - Update to version 0.7 - use spec_query instead of output_versions using the specfile parser from the build package (boo#1059858) Package 'osc': - update to version 0.162.0 - add Recommends: ca-certificates to enable TLS verification without manually installing them. (bnc#1061500)
References: https://www.suse.com/support/update/announcement/2017/suse-su-20173253-1/, https://bugzilla.suse.com/1059858, https://bugzilla.suse.com/1061500, https://bugzilla.suse.com/1069904, https://bugzilla.suse.com/665768, https://bugzilla.suse.com/938556, https://www.suse.com/security/cve/CVE-2010-4226, https://www.suse.com/security/cve/CVE-2017-14804, https://www.suse.com/security/cve/CVE-2017-9274
Affected packages
Package
Name: build
Purl: pkg:rpm/suse/build&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2
Affected ranges
Type: ECOSYSTEM
Events:
