Upstream information
Description
Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to execute arbitrary commands via shell metacharacters in an unspecified FileUtils function call.NVD CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Novell/SUSE information
Novell Bugzilla entry: 701815 SUSE Security Advisories:- SUSE-SU-2011:0917-1, published Thu, 18 Aug 2011 09:08:24 +0200 (CEST)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Studio Onsite 1.1 [Appliance - Studio] |
| studioonsite1.1.x86-64 SAT Patch Nr: 4998 |
