Candidate: CVE-2017-9274 PublicDate: 2018-03-01 20:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9274 https://github.com/openSUSE/osc/commit/f0325eb0b58c266eb0905ccf827dc7eb864378a1 Description: A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files with specific macro constructs. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_osc: upstream_osc: released (0.162.1-1) precise/esm_osc: DNE trusty_osc: ignored (reached end-of-life) trusty/esm_osc: DNE (trusty was needed) xenial_osc: ignored (end of standard support, was needed) artful_osc: ignored (reached end-of-life) bionic_osc: not-affected (0.162.1-1) cosmic_osc: not-affected (0.162.1-1) disco_osc: not-affected (0.162.1-1) eoan_osc: not-affected (0.162.1-1) focal_osc: not-affected (0.162.1-1) groovy_osc: not-affected (0.162.1-1) hirsute_osc: not-affected (0.162.1-1) impish_osc: not-affected (0.162.1-1) jammy_osc: not-affected (0.162.1-1) devel_osc: not-affected (0.162.1-1)