Permissions, Privileges, and Access Controls in osc - CVE-2024-22034

 

Permissions, Privileges, and Access Controls in osc - CVE-2024-22034

Published: September 4, 2024


Vulnerability identifier: #VU96795
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-22034
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to overwrite arbitrary files on the system.

The vulnerability exists due to improper access restrictions. A local user can overwrite arbitrary files on the system.


Affected software

osc
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
Fedora
Development Tools Module
openSUSE Leap
openEuler
osc
osc-help

How to mitigate CVE-2024-22034

Install updates from vendor's website.

osc - addressed in versions 1.9.1, 0.183.0-15.18.1, 1.9.0-150400.10.6.1
osc - update to 0.177.0-2
osc-help - update to 0.177.0-2
osc - addressed in versions 1.9.1-420.1.1.el9, 1.9.1-420.1.1.fc39, 1.9.1-420.1.1.fc40, 1.9.1-420.1.1.fc41

External References

Related Security Bulletins