CVE-2015-0778
published 2015-03-16CVE-2015-0778: osc before 0.151.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a _service file.
PriorityP351high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.61%
88.2th percentile
osc before 0.151.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a _service file.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | osc | < osc 0.149.0-2 (bookworm) | osc 0.149.0-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | osc | >= 0 < 0.149.0-2 | 0.149.0-2 |
| opensuse | osc | >= 0 < 0.149.0-2 | 0.149.0-2 |
| opensuse | osc | >= 0 < 0.149.0-2 | 0.149.0-2 |
| opensuse | osc | >= 0 < 0.149.0-2 | 0.149.0-2 |
| suse | opensuse_osc | <= 0.150 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4hfv-g6pr-5qh7: osc before 0
ghsa_unreviewed·2022-05-14
CVE-2015-0778 [HIGH] CWE-77 GHSA-4hfv-g6pr-5qh7: osc before 0
osc before 0.151.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a _service file.
OSV
CVE-2015-0778: osc before 0
osv·2015-03-16·CVSS 7.5
CVE-2015-0778 [HIGH] CVE-2015-0778: osc before 0
osc before 0.151.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a _service file.
Debian
CVE-2015-0778: osc - osc before 0.151.0 allows remote attackers to execute arbitrary commands via she...
vendor_debian·2015·CVSS 7.5
CVE-2015-0778 [HIGH] CVE-2015-0778: osc - osc before 0.151.0 allows remote attackers to execute arbitrary commands via she...
osc before 0.151.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a _service file.
Scope: local
bookworm: resolved (fixed in 0.149.0-2)
bullseye: resolved (fixed in 0.149.0-2)
forky: resolved (fixed in 0.149.0-2)
sid: resolved (fixed in 0.149.0-2)
trixie: resolved (fixed in 0.149.0-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1233 chromium-browser: combination of V8, Gamepad and IPC bugs that can lead to remote code execution
bugzilla·2015-04-02·CVSS 7.5
CVE-2015-1233 [HIGH] CVE-2015-1233 chromium-browser: combination of V8, Gamepad and IPC bugs that can lead to remote code execution
CVE-2015-1233 chromium-browser: combination of V8, Gamepad and IPC bugs that can lead to remote code execution
Multiple unspecified flaws were found in the V8, Gamepad and IPC components of the Chromium browser that allow remote code execution outside of sandbox:
https://code.google.com/p/chromium/issues/detail?id=469058
External References:
http://googlechromereleases.blogspot.com/2015/04/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0778 https://rhn.redhat.com/errata/RHSA-2015-0778.html
Bugzilla
CVE-2015-1234 chromium-browser: buffer overflow via race condition in GPU
bugzilla·2015-04-02·CVSS 6.8
CVE-2015-1234 [MEDIUM] CVE-2015-1234 chromium-browser: buffer overflow via race condition in GPU
CVE-2015-1234 chromium-browser: buffer overflow via race condition in GPU
An unspecified flaws was found in the GPU component of the Chromium browser that leads to buffer overflow:
https://code.google.com/p/chromium/issues/detail?id=468936
External References:
http://googlechromereleases.blogspot.com/2015/04/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0778 https://rhn.redhat.com/errata/RHSA-2015-0778.html
Bugzilla
CVE-2015-0778 osc: osc _service file shell injection flaw
bugzilla·2015-03-13·CVSS 7.5
CVE-2015-0778 [HIGH] CVE-2015-0778 osc: osc _service file shell injection flaw
CVE-2015-0778 osc: osc _service file shell injection flaw
A server and client side arbitrary command execution flaw was found in the source service handling of OBS.
More information along with a patch in Suse's bug report and announcement:
https://bugzilla.novell.com/show_bug.cgi?id=901643
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00012.html
Discussion:
Created osc tracking bugs for this issue:
Affects: fedora-all [bug 1201774]
---
osc-0.151.1-163.2.1.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
---
osc-0.151.1-163.2.1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
---
osc-0.151.1-163.2.1.fc21 has
Bugzilla
CVE-2015-0778 osc: osc _service file shell injection flaw [fedora-all]
bugzilla·2015-03-13·CVSS 7.5
CVE-2015-0778 [HIGH] CVE-2015-0778 osc: osc _service file shell injection flaw [fedora-all]
CVE-2015-0778 osc: osc _service file shell injection flaw [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154257.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/154267.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/154117.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00012.htmlhttp://www.securityfocus.com/bid/73114https://bugzilla.suse.com/show_bug.cgi?id=901643https://security.gentoo.org/glsa/201603-02http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154257.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/154267.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/154117.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00012.htmlhttp://www.securityfocus.com/bid/73114https://bugzilla.suse.com/show_bug.cgi?id=901643https://security.gentoo.org/glsa/201603-02
2015-03-16
Published