« Back to list

CVE-2015-0796

Status: ModifiedHigh (7.8)—

In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could generate non-standard files like symlinks or device nodes, which could allow buildservice users to break of confinement or cause denial of service attacks on the source service.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2015-0796",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "security@opentext.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 6.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@opentext.com",
      "affectedData": [
        {
          "vendor": "SUSE",
          "product": "open build service",
          "versions": [
            {
              "status": "affected",
              "version": "2.6",
              "lessThan": "2.6.3",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2.5",
              "lessThan": "2.5.7",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2.4",
              "lessThan": "2.4.8",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-03-02T20:29:00.207",
  "references": [
    {
      "url": "https://bugzilla.suse.com/show_bug.cgi?id=941099",
      "source": "security@opentext.com"
    },
    {
      "url": "https://github.com/openSUSE/open-build-service/commit/474a3db19498765f0118ba3dbc0b1cc90b0097fc",
      "source": "security@opentext.com"
    },
    {
      "url": "https://bugzilla.suse.com/show_bug.cgi?id=941099",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/openSUSE/open-build-service/commit/474a3db19498765f0118ba3dbc0b1cc90b0097fc",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@opentext.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-434"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-59"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could generate non-standard files like symlinks or device nodes, which could allow buildservice users to break of confinement or cause denial of service attacks on the source service."
    },
    {
      "lang": "es",
      "value": "n open buildservice, en versiones 2.6 anteriores a la 2.6.3, versiones 2.5 anteriores a la 2.5.7 y versiones 2.4 anteriores a la 2.4.8, la aplicación origen de parche de servicio podría generar archivos no estándar como symlinks o nodos de dispositivo. Esto podría permitir que los usuarios buildservice salgan de su confinamiento o provoquen ataques de denegación de servicio (DoS) en el servicio origen."
    }
  ],
  "lastModified": "2026-06-17T00:20:54.790",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:opensuse:open_buildservice:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E4AF3CA3-F883-4301-85CD-2C71DB0FD6F3",
              "versionEndExcluding": "2.4.8",
              "versionStartIncluding": "2.4"
            },
            {
              "criteria": "cpe:2.3:a:opensuse:open_buildservice:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "701DD07C-6709-4E18-A2A5-BEF1482B21FC",
              "versionEndExcluding": "2.5.7",
              "versionStartIncluding": "2.5"
            },
            {
              "criteria": "cpe:2.3:a:opensuse:open_buildservice:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5241ECAA-7075-4CD1-87D3-5ADD1840E81E",
              "versionEndExcluding": "2.6.3",
              "versionStartIncluding": "2.6"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@opentext.com"
}